CTIPilot

Cisco ISE Passive Identity Connector

product · product:cisco-ise-passive-identity-connector

Coverage timeline
1
first 2026-09-17 → last 2026-09-17
Peak priority
critical
1 critical
Sources cited
7
4 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
5
see Co-occurring entities below
ATT&CK techniques
2
pinned v19.2 · see below

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-17/cve-2026-76460-cisco-ise-auth-bypass-root-rce · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-09-17/cve-2026-76460-cisco-ise-auth-bypass-root-rce · ATT&CK page ↗

Story timeline

  1. 2026-09-17CVE-2026-76460 (+ CVE-2026-76423), Cisco Identity Services Engine: unauthenticated API authentication bypass to root, found while resolving a customer support case, no workaround beyond ACLs (CVSS 10.0)
    trending-vulnerabilitiesCisco confirms active exploitation of an unauthenticated ISE API bypass that can reach root, found while resolving a customer support case

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • sec.cloudapps.cisco.com3 (43%)
  • cisa.gov2 (29%)
  • advisories.ncsc.nl1 (14%)
  • cert.ssi.gouv.fr1 (14%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Cisco ISE Passive Identity Connector (1)

2026-09-17 · view entry permalink →

CRITICALCVE-2026-76460 +3exploitedupdatedNATOA1

CVE-2026-76460 (+ CVE-2026-76423), Cisco Identity Services Engine: unauthenticated API authentication bypass to root, found while resolving a customer support case, no workaround beyond ACLs (CVSS 10.0)

Cisco disclosed CVE-2026-76460 (CVSS 3.1 10.0, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) on 2026-09-16: an unauthenticated, remote attacker can bypass authentication on an API endpoint of Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) due to insufficient authentication control, affecting every release "regardless of device configuration" (Cisco PSIRT, 2026-09-16). Cisco confirms the flaw was found while resolving a customer's TAC support case, not internal research, and states it is aware of active exploitation (Cisco PSIRT, 2026-09-16); a successful exploit bypasses the web-based management interface entirely and, per Cisco's own advisory, "threat actors may obtain command execution with root privileges" (Cisco PSIRT, 2026-09-16). There is no workaround; the only mitigation is restricting management-plane access via infrastructure ACLs. Fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4; Cisco ISE 3.0 has reached End of Software Maintenance and must migrate to a supported, fixed release (Cisco PSIRT, 2026-09-16). CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day (CISA, 2026-09-16), with a remediation due date of 2026-09-19, three days out (CISA KEV JSON feed, 2026-09-16).

This CVE was part of a bundled disclosure of 15 distinct Cisco ISE advisories the same day (Cisco PSIRT, 2026-09-16). A sibling flaw, CVE-2026-76423 (CVSS 10.0, also unauthenticated and affecting every release "regardless of device configuration"), removes the same authentication boundary via a separate API endpoint, letting an attacker read or modify ISE configuration and identity data with administrative privileges; Cisco states it is "not aware of any public announcements or malicious use" of this second flaw as of disclosure, but it shares the same fixed-release schedule (Cisco PSIRT, 2026-09-16). Cisco ISE is standard 802.1X/network-access-control and identity infrastructure across enterprise and public-sector networks, so an unauthenticated bypass of its management/API surface is a direct path to defeating an organization's network access controls.

Triage: a legitimate administrative session against the ISE API originates from an authenticated, known management source; the discriminator here is that exploitation reaches the API without any authentication at all, so any successful request against the affected endpoint from outside expected management-plane sources is itself the signal, and because a root-level attacker can edit or delete access.log entries, an apparently clean on-box log is not evidence of an intact device. Cisco's guidance is to corroborate against firewall and network logs external to the ISE node for unexpected outbound uploads or downloads to unfamiliar IP addresses.

The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.

This vulnerability was found during the resolution of a Cisco Technical Assistance Center (TAC) support case.

Upon successful exploitation of this vulnerability, threat actors may obtain command execution with root privileges.

Cisco PSIRT 2026-09-16

Of the 21 vulnerabilities in total, 13 are rated critical. Based on the CVSS scores Cisco published, four vulnerabilities can be exploited remotely without authentication. (translated from Dutch)

Four vulnerabilities, CVE-2026-20130, CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460, have a CVSS score of 10.0. (translated from Dutch)

NCSC-NL (NCSC-2026-0382) 2026-09-17
Updaterun 2026-09-18T0410Z-intelcvessourcesevidencebody

CVE-2026-76460 was one part of a much larger Cisco ISE hardening release the same day. NCSC-NL's advisory scopes 21 of the disclosed vulnerabilities and states: "Of the 21 vulnerabilities in total, 13 are rated critical. Based on the CVSS scores Cisco published, four vulnerabilities can be exploited remotely without authentication" (translated from Dutch) (NCSC-NL, 2026-09-17). Two further CVEs join the maximum-severity tier alongside the already-covered CVE-2026-76460 and CVE-2026-76423: "Four vulnerabilities, CVE-2026-20130, CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460, have a CVSS score of 10.0" (translated from Dutch) (NCSC-NL, 2026-09-17); Cisco groups multiple underlying flaws sharing a CWE classification for a hardening release under one CVE ID, with the CVSS score representing the highest-scoring underlying flaw in each bundle. CERT-FR's own combined advisory states plainly that Cisco reports only CVE-2026-76460 as actively exploited, no other CVE in the release is named exploited by any source (CERT-FR, 2026-09-17). The same advisory notes that ISE 3.1 and 3.2, both scheduled for end-of-software-maintenance on 30 November 2027, will not receive a fix at all for eight of the disclosed CVEs; any organization on those release trains has an unpatchable subset of this disclosure and should treat an upgrade to 3.3 or later as the only remediation path for those specific flaws (CERT-FR, 2026-09-17).

vulnerability17 Sep 04:31Zmulti-sourceOpen finding ↗