Cisco ISE authentication bypass, CVSS 10, was exploited before the patch
CVE-2026-76460 lets an unauthenticated attacker bypass Cisco Identity Services Engine's management interface through an API endpoint and run commands as root. Cisco confirmed active exploitation; CISA gave federal agencies until September 19.
Cisco disclosed CVE-2026-76460, a maximum-severity (CVSS 10.0) flaw in Identity Services Engine (ISE) and ISE Passive Identity Connector, and confirmed it is being exploited in the wild. Insufficient authentication on an API endpoint lets an unauthenticated attacker bypass the web management interface and, per Cisco, obtain command execution as root. Releases 3.1 through 3.5 are affected; the fixes are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. There is no workaround beyond restricting management traffic with infrastructure access lists. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 16 with a September 19 deadline. Cisco's detection guidance is to search the ISE ise-kong/access.log for the username dummyuser. It has not said who is exploiting the flaw or how many customers were hit.
Why it matters
ISE is the policy engine that decides which users and devices get onto the network, over RADIUS and TACACS+. It stores the shared secrets for every switch, wireless controller and VPN concentrator that asks it for a decision, and it is usually joined to Active Directory as an identity source. Root on ISE is therefore not one compromised appliance; it is the ability to rewrite who is allowed on the network and a store of credentials trusted by everything else.
This is the second maximum-severity Cisco management flaw in a week, after the Secure FMC bypass that attackers used to harvest RADIUS and LDAP bind accounts. The shared lesson is to treat these consoles as tier-zero identity infrastructure: management interfaces reachable only from an admin network, and, after patching, rotation of the RADIUS secrets and directory accounts the box held, because patching closes the door without changing the locks. Cisco's advisory is cisco-sa-ISE-ABP-VNSW7Tn5.
Source: The Hacker News
Related on Start with Identity
- BlogA 9.8-CVSS vCenter authentication bypass has no workaround, only an emergency patch
Broadcom shipped emergency fixes for three critical VMware flaws, including CVE-2026-59309 (CVSS 9.8), which lets any attacker with network access to vCenter by
- BlogFortinet's January SSO bypass hit boxes already patched for December's SAML bug
CVE-2026-24858 is the follow-on FortiCloud SSO SAML bypass. Devices patched for CVE-2025-59718 and 59719 were still exploitable. Actively exploited. CISA guidan
- BlogCisco FMC shipped with hardcoded credentials, and attackers found them before the patch did
CVE-2026-20316 is a low-privileged account with credentials hardcoded into Cisco Secure Firewall Management Center, giving unauthenticated remote attackers acce
- CVEFortinet follow-on SSO SAML bypass after the 59718 patch
A second FortiCloud SSO SAML bypass that hits devices already patched for CVE-2025-59718 and CVE-2025-59719. Actively exploited. CISA guidance 28 January 2026.
- CVEIvanti Connect Secure authentication bypass
Connect Secure and Policy Secure skipped authentication on a path that later chained with CVE-2024-21887 for unauthenticated RCE. CISA KEV. January 2024 disclos
- CVEIvanti Sentry authentication bypass
Ivanti Sentry (MobileIron Sentry) skipped authentication on an administrative API. CISA KEV. August 2023. The gateway in front of EPMM had its own unlocked door