Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
A critical zero-day vulnerability in Cisco Identity Services Engine (ISE) is actively being exploited, prompting Cisco to release emergency patches. Attackers can bypass authentication controls and gain root access, potentially allowing them to hide evidence of compromise and execute commands on the affected device. Federal agencies are urged to patch the vulnerability within three days.
Cisco released urgent patches for a critical-severity authentication bypass vulnerability in Identity Services Engine (ISE) on Wednesday. Tracked as CVE-2026-76460 (CVSS score of 10/10), this security defect impacts an API endpoint of the appliance, which does not apply sufficient authentication controls. This allows an attacker to send crafted requests to the API and bypass the web-based management interface to gain access to the affected device. Both Cisco ISE and ISE Passive Identity Connector (ISE-PIC) are affected, regardless of device configuration. While no workarounds exist, using infrastructure access control lists (iACLs) to restrict traffic to the affected device prevents remote exploitation. Cisco PSIRT is aware of active exploitation of this vulnerability and strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability. The US cybersecurity agency CISA added the zero-day to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, in line with BOD 26-04 requirements. To hunt for potential compromises, organizations should review ‘access.log’ for suspicious usernames. For distributed deployments, the logs for each node should be checked. The presence of any entry in the output may indicate malicious activity, and it is strongly recommended to re-image the affected nodes and restore from configuration backup if needed. Additionally, Cisco warns that successful exploitation of CVE-2026-76460 can enable attackers to execute commands with root privileges, which would allow them to hide or delete indicators of compromise (IoCs). Cross-checking network logs and firewall logs outside of the impacted device should help administrators discover potential compromises, including unexpected uploads/downloads.