CVE-2026-76460
Cisco Identity Services Engine authentication bypass lets unauthenticated attackers access the web management interface (CVE-2026-76460)
Cisco Identity Services Engine has a critical API authentication bypass allowing unauthenticated remote access to the web management interface. CISA KEV and Cisco PSIRT confirm active exploitation. Apply Cisco's iACL mitigation, restrict exposure, and upgrade to a fixed software release.
What happened
Cisco Identity Services Engine (ISE) has an API endpoint with insufficient authentication controls. An unauthenticated attacker who can reach that endpoint can send a crafted request and bypass authentication for the web-based management interface. The vulnerability is rated critical with a CVSS 3.1 score of 10. It is exploitable over the network with low attack complexity, requires no privileges and no user interaction, and has high impact on confidentiality, integrity and availability, with changed scope.
CISA added CVE-2026-76460 to the Known Exploited Vulnerabilities catalog on 2026-09-16 with a due date of 2026-09-19. CISA SSVC rates exploitation as active and automatable, with total technical impact. Cisco PSIRT states that it is aware of active exploitation of this vulnerability.
Who is affected
Cisco lists Cisco Identity Services Engine Software versions 3.1.0 p8, 3.1.0 p9, 3.2.0 p7, 3.3 Patch 1, 3.3 Patch 2, 3.3 Patch 3, 3.3 Patch 4 and 3.4.0 as affected. Cisco ISE Passive Identity Connector versions 3.4.0 and 3.5.0 are also affected. ISE typically acts as a policy and access control engine, so a bypass of its web management interface is a significant control-plane exposure.
What to do now
- Apply Cisco's mitigation now: use infrastructure access control lists (iACLs) to allow only required management and control plane traffic destined to the affected device. Cisco states there are no workarounds that address this vulnerability.
- Restrict network exposure of ISE and Passive Identity Connector management interfaces. The vulnerability is remotely exploitable without credentials, so any affected interface reachable from an untrusted network should be treated as exposed.
- Upgrade to a fixed software release. Cisco strongly recommends that customers upgrade to a fixed software release; the fixed release identifiers are not listed in the data provided here, so confirm the appropriate release in Cisco's advisory.
- If a fixed release or acceptable mitigation cannot be applied, follow CISA's BOD 26-04 guidance, including discontinuing use of the product where mitigations are unavailable.
How to detect it
Cisco has not published specific indicators of compromise for this vulnerability. Because the flaw bypasses web-based management interface authentication, teams should review unexpected administrative access to affected ISE and Passive Identity Connector instances, and confirm that management interfaces are not reachable from untrusted networks.
Beyond the patch
This is a network-reachable authentication bypass in an access control product, and it is already in CISA's Known Exploited Vulnerabilities catalog. An ISE management interface reachable from the wrong network is the exposure this vulnerability depends on. Virtual CISO Services can help identify exposed management planes and prioritise remediation; for organisations responding to active exploitation, Managed Detection and Response provides detection and response around post-exploitation activity.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Cisco Identity Services Engine Software | 3.1.0 p8 3.1.0 p9 3.3 Patch 2 3.3 Patch 1 3.3 Patch 3 3.4.0 3.2.0 p7 3.3 Patch 4 | No fixed version listed yet |
| Cisco ISE Passive Identity Connector | 3.4.0 3.5.0 | No fixed version listed yet |