CVE-2026-76460 (CVSS 10.0): Cisco ISE Authentication Bypass Zero-Day Exploited in Wild — CISA Orders Emergency Patch
Your network’s identity enforcer just became an attacker’s front door. On September 16, 2026, Cisco confirmed that CVE-2026-76460 — a maximum-severity, no-authentication-required zero-day in its Identity Services Engine (ISE) — is actively being exploited in the wild. With a CVSS 3.1 score of 10.0, this isn’t a vulnerability you schedule for your next quarterly patch window. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog the same day and issued a binding deadline: U.S. federal civilian agencies must patch by September 19, 2026 — just three days after discovery. For every enterprise relying on Cisco ISE as the gatekeeper to their zero-trust architecture, the clock is ticking.
- CVE-2026-76460 is a CVSS 10.0 authentication bypass in Cisco ISE and ISE-PIC, allowing remote unauthenticated root shell access.
- Cisco discovered the flaw while handling a live customer compromise — real-world exploitation was already underway at disclosure.
- CISA added it to the KEV catalog on September 16, 2026, with a 3-day federal patch mandate (deadline: September 19, 2026).
- Affected: all ISE/ISE-PIC versions prior to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4.
- Because ISE controls network access policy for every device on the enterprise network, a compromised appliance gives attackers policy-level access to your entire estate.
- No full workaround exists — patching is the only fix; infrastructure ACLs are a temporary compensating control only.
- Indian BFSI, GCC, and enterprise organizations with Cisco ISE deployments should treat this as a P1 incident response scenario today.
What Is Cisco ISE — and Why Does Compromising It Change Everything?
Cisco Identity Services Engine is the central nervous system of enterprise network access control. ISE authenticates every user and device seeking entry to the corporate network using 802.1X, RADIUS, and TACACS+ protocols, enforces role-based access policies, maintains posture assessments, and acts as the policy enforcement hub in zero-trust network access (ZTNA) architectures. In short, ISE decides who can talk to what on your network.
That role makes it extraordinarily valuable — and extraordinarily dangerous — as a target. An attacker who owns your ISE appliance doesn’t just get one server. They get the policy engine that governs every other device, server, and network segment you protect. They can quietly grant themselves administrative access, strip existing policy controls from specific segments, harvest stored RADIUS shared secrets and certificates, and erase their tracks from access logs — all from a position of legitimate authority within your own infrastructure.
This is precisely why CVE-2026-76460 earned a full CVSS 10.0 score, and why CISA’s response was measured in hours, not days.
Technical Breakdown: How CVE-2026-76460 Works
The vulnerability lives in the Kong API Gateway layer that Cisco introduced in ISE 3.1 to route its Monitoring APIs, External RESTful Services (ERS) APIs, and Open APIs to the web-based management interface. A crafted HTTP request sent to a specific endpoint in this gateway layer bypasses the authentication check that is supposed to validate sessions before granting access to the management plane.
The result is that a remote, unauthenticated attacker who can reach the ISE management interface over the network can:
- Send a single crafted HTTP request to the vulnerable API endpoint
- Bypass ISE’s web management authentication entirely
- Achieve root-level command execution on the appliance
No credentials. No user interaction. No foothold required inside the network — only network reachability to the ISE management plane.
| Attribute | Detail |
|---|---|
| CVE ID | CVE-2026-76460 |
| CVSS 3.1 Score | 10.0 (Critical) |
| Attack Vector | Network |
| Authentication | None required |
| Privileges Required | None |
| User Interaction | None |
| Impact | Root command execution on ISE appliance |
| Affected | ISE/ISE-PIC 3.1–3.5 (all versions prior to emergency patches) |
| CISA KEV Added | September 16, 2026 |
| Federal Patch Deadline | September 19, 2026 |
Active Exploitation: Cisco PSIRT Found This in a Customer Compromise
The most alarming aspect of CVE-2026-76460 is how it was discovered. Cisco’s Product Security Incident Response Team (PSIRT) did not find this vulnerability through internal research, a bug bounty report, or a coordinated disclosure — they found it while resolving an active customer support case. An enterprise had already been compromised, and the investigation traced the intrusion back to this authentication bypass.
That means the window between exploitation beginning and the patch being available was non-zero in the worst possible way: attackers knew how to weaponize this before defenders knew it existed. As of September 17, 2026, no public proof-of-concept exploit has been released, and Cisco and CISA have not publicly attributed the known attack to a specific threat actor or nation-state group. However, the target profile — enterprise NAC infrastructure — is consistent with both ransomware pre-positioning operations (where operators spend weeks elevating access and disabling defenses before deploying ransomware) and state-sponsored espionage campaigns interested in harvesting credentials and mapping enterprise network topology.
For more context on how threat actors are increasingly targeting enterprise security infrastructure as a lateral movement enabler, see Cisco’s own advisory and the CISA KEV catalog entry for this vulnerability. (BleepingComputer coverage | The Hacker News analysis | CISA KEV Catalog)
India Alert: Why BFSI and GCC Organizations Are Especially at Risk
Cisco ISE is among the most widely deployed NAC solutions across India’s enterprise and regulated-industry landscape. Indian BFSI institutions — including large public and private sector banks in Mumbai, Hyderabad, and Bangalore — have standardized on ISE for 802.1X enforcement in compliance with RBI cybersecurity guidelines that mandate network segmentation and identity-based access control. Global Capability Centres (GCCs) running hybrid Azure AD environments have similarly adopted ISE as the on-premises NAC complement to their cloud identity stacks.
Under CERT-In’s 2022 directive, Indian organizations must report cybersecurity incidents — including any compromise of critical infrastructure — within six hours. A compromised ISE appliance would almost certainly qualify: it controls network policy for the entire enterprise. Any organization that discovers exploitation after the fact faces not only the operational damage of a full NAC compromise but also a mandatory CERT-In reporting obligation with a very short clock.
This context makes CVE-2026-76460 a board-level risk conversation for every CISO in India running a Cisco ISE deployment — not a ticket for the patching team to handle next sprint.
What You Should Do Right Now: Sanjay Seth’s Zero-Trust Perspective
As a cybersecurity consultant who has deployed and hardened Cisco ISE environments across India’s BFSI and enterprise sectors, I recommend treating this as an incident response scenario from this moment, not a routine patch. Here is the prioritized action list:
-
Patch immediately. Deploy the emergency patches Cisco released on September 16, 2026:
- ISE/ISE-PIC 3.5 → Patch 4
- ISE/ISE-PIC 3.4 → Patch 7
- ISE/ISE-PIC 3.3 → Patch 12
- ISE/ISE-PIC 3.2 → Patch 11
- ISE/ISE-PIC 3.1 → Patch 12
- Restrict ISE management plane access immediately. Deploy infrastructure access control lists (iACLs) on the routers and switches upstream of your ISE appliance to limit management plane reachability to only your administrative management subnets. This is the only compensating control available — it does not fix the vulnerability but removes the network path an unauthenticated attacker needs to exploit it.
- Audit ISE access logs for anomalous API calls. Review ISE operational audit logs for any unexpected API calls to the External RESTful Services (ERS) API, Monitoring API, or Open API endpoints, particularly from non-administrative source IPs. Treat any such activity as a confirmed compromise indicator.
- Rotate RADIUS shared secrets and certificates. A compromised ISE appliance exposes all stored RADIUS shared secrets and certificate material. Even if your audit shows no evidence of compromise, proactive rotation closes the window on secrets that may have been exfiltrated silently.
- Validate your network segmentation. Run a policy audit on ISE to confirm that your network access policies are intact and have not been modified. Pay particular attention to any policy changes that might have been made in the past 30 days — the exploitation window may extend back further than the disclosure date.
- File a CERT-In report if any indicators of compromise are found. Under the 6-hour reporting requirement, this is not optional for Indian organizations. Have your IR template ready before you start the investigation.
For deeper guidance on structuring your network access control posture under a zero-trust framework — including ISE architecture reviews that reduce the blast radius of exactly this class of vulnerability — see how similar Cisco infrastructure vulnerabilities have been handled at the enterprise level, or review the FortiGate PivotC2 RAT incident for how NAC-adjacent appliances are weaponized once compromised.
You can also read Cisco’s official advisory and the SecurityWeek technical coverage for vendor-level guidance: (SecurityWeek | Help Net Security)
Frequently Asked Questions
Is Cisco ISE-PIC also affected by CVE-2026-76460?
Yes. Cisco’s advisory explicitly covers both Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Both products share the same underlying API gateway architecture introduced in version 3.1, making both vulnerable. Organizations running ISE-PIC for passive identity mapping in hybrid environments should apply the same patch versions listed above.
Can network segmentation protect us if we can’t patch immediately?
Partially. Restricting access to the ISE management plane using infrastructure access control lists (iACLs) removes the network path an attacker needs to exploit this vulnerability. However, this is a compensating control, not a fix. If your ISE management interface must be reachable from a broader subnet for operational reasons — a common reality in large enterprise environments — your exposure is not fully mitigated until you apply the patch. Prioritize patching; use iACLs as a bridge while you schedule the maintenance window.
How do we know if we’ve already been compromised?
Cisco PSIRT discovered this vulnerability during an active customer compromise, which means exploitation was occurring before the patch existed. Key indicators to investigate: unexpected API calls in ISE operational audit logs (particularly from non-administrative source IPs), unexplained policy changes in your ISE configuration, new administrator accounts you did not create, and modifications to your RADIUS client configurations. If you find any of these, escalate to incident response — and in India, initiate the CERT-In reporting process.
Does this vulnerability affect Cisco ISE on Cisco UCS or VMware-based deployments?
Yes. CVE-2026-76460 is a software vulnerability in the ISE application itself, not in the underlying hardware or hypervisor. It affects all supported deployment models — physical Cisco Secure Network Server (SNS) appliances, VMware ESXi-based virtual deployments, and any other supported virtualization platform. The attack surface is the exposed management interface regardless of where the ISE application is hosted.
Is Your ISE Deployment Patched — and Is Your Zero-Trust Architecture Built to Limit the Blast Radius?
A CVSS 10.0 vulnerability in your NAC engine isn’t just a patch ticket — it’s a question about whether your security architecture is designed to contain a worst-case compromise. If you’re running Cisco ISE across your enterprise and want a structured assessment of your network access control posture, segmentation architecture, and incident response readiness, get in touch for a security consultation. Whether you’re in BFSI, government, or enterprise IT in India’s NCR and beyond, we’re here to help you move from exposure to confidence.