Start with Identity
News

Cisco ISE authentication bypass, CVSS 10, was exploited before the patch

CVE-2026-76460 lets an unauthenticated attacker bypass Cisco Identity Services Engine's management interface through an API endpoint and run commands as root. Cisco confirmed active exploitation; CISA gave federal agencies until September 19.

By SWI Community TeamSep 17, 2026

Cisco disclosed CVE-2026-76460, a maximum-severity (CVSS 10.0) flaw in Identity Services Engine (ISE) and ISE Passive Identity Connector, and confirmed it is being exploited in the wild. Insufficient authentication on an API endpoint lets an unauthenticated attacker bypass the web management interface and, per Cisco, obtain command execution as root. Releases 3.1 through 3.5 are affected; the fixes are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. There is no workaround beyond restricting management traffic with infrastructure access lists. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 16 with a September 19 deadline. Cisco's detection guidance is to search the ISE ise-kong/access.log for the username dummyuser. It has not said who is exploiting the flaw or how many customers were hit.

Why it matters

ISE is the policy engine that decides which users and devices get onto the network, over RADIUS and TACACS+. It stores the shared secrets for every switch, wireless controller and VPN concentrator that asks it for a decision, and it is usually joined to Active Directory as an identity source. Root on ISE is therefore not one compromised appliance; it is the ability to rewrite who is allowed on the network and a store of credentials trusted by everything else.

This is the second maximum-severity Cisco management flaw in a week, after the Secure FMC bypass that attackers used to harvest RADIUS and LDAP bind accounts. The shared lesson is to treat these consoles as tier-zero identity infrastructure: management interfaces reachable only from an admin network, and, after patching, rotation of the RADIUS secrets and directory accounts the box held, because patching closes the door without changing the locks. Cisco's advisory is cisco-sa-ISE-ABP-VNSW7Tn5.

Source: The Hacker News

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.