Vulnerability
Published 2026-09-16
Verified 2026-09-19

Cisco ISE / ISE-PIC API auth bypass CVE-2026-76460 (CVSS 10.0); zero-day exploited; CISA KEV

Cisco PSIRT advisory cisco-sa-ISE-ABP-VNSW7Tn5 (first published 16 September 2026 16:00 GMT) covers CVE-2026-76460, a maximum-severity authentication bypass in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of configuration. Insufficient authentication control on an API endpoint lets an unauthenticated remote attacker send a crafted request and bypass the web-based management interface to gain unauthorised device access; Cisco notes successful exploitation may yield root command execution and that on-box evidence can be removed afterward. Cisco CVSS 3.1 base 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H); CWE-648; Bug CSCww39530. No workarounds; temporary mitigation: infrastructure ACLs restricting management/control-plane traffic to the device. Fixed software: ISE/ISE-PIC 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11, 3.1 Patch 12. Cisco PSIRT is aware of active exploitation; CISA added CVE-2026-76460 to KEV on 16 September 2026 (same alert also added Acronis CVE-2026-87886). Same-day Cisco ISE/ISE-PIC criticals including CVE-2026-76423 are noted as related context, not separate desk cards — only 76460 has claimed in-the-wild use in the PSIRT advisory. Hunt ise-kong/access.log for suspicious usernames and correlate off-box network/firewall logs. Primary: Cisco PSIRT; wires: BleepingComputer / SecurityWeek 17 Sep 2026.

Product
Cisco Identity Services Engine (ISE); Cisco ISE Passive Identity Connector (ISE-PIC)
Versions
Affected ISE/ISE-PIC 3.1–3.5 lines prior to fixed patches; fix: 3.5 Patch 4 / 3.4 Patch 7 / 3.3 Patch 12 / 3.2 Patch 11 / 3.1 Patch 12
CVSS
Exploited in Australia?
unknown
Patch to
Upgrade ISE/ISE-PIC to listed fixed patches immediately; until then restrict management plane with iACLs; hunt access.log / off-box logs for abuse

Primary: Cisco PSIRT cisco-sa-ISE-ABP-VNSW7Tn5 (CVE-2026-76460, 16 Sep 2026) · Vendor: Cisco Security Advisory — ISE authentication bypass · CVE: CVE-2026-76460, CVE-2026-87886, CVE-2026-76423 · BleepingComputer (17 Sep 2026); also SecurityWeek; CISA KEV alert 16 Sep

vulnerabilities identity network