Cyber One Solutions logo.
Get Support

Security Advisory

CVE-2026-76460: Cisco Confirms Active Exploitation of a Maximum-Severity ISE Bypass

September 17, 2026 · Cyber One Solutions Security Team

Cisco disclosed a CVSS 10.0 authentication bypass in Identity Services Engine that lets an unauthenticated attacker take over the system that decides which devices and users get on your network. CISA added it to the Known Exploited Vulnerabilities catalog the same day, with a three-day federal remediation window.

Cisco published security advisory cisco-sa-ISE-ABP-VNSW7Tn5 on September 16, 2026, disclosing CVE-2026-76460, an authentication bypass in Identity Services Engine (ISE) that carries a maximum CVSS v3.1 base score of 10.0. In the same advisory, Cisco stated plainly that "the Cisco PSIRT is aware of active exploitation of this vulnerability." CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog that same day, September 16, 2026, listing it as the "Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability" and setting a remediation due date of September 19, 2026, only three days out, for federal civilian agencies under Binding Operational Directive 26-04, according to Cisco's security advisory and CISA's Known Exploited Vulnerabilities catalog.

What Identity Services Engine Controls, and Why a Bypass Here Is Different

Cisco ISE is network access control (NAC) infrastructure. It is the system that decides which devices and users are allowed onto a network in the first place, handling 802.1X authentication at the switch and wireless level, guest and BYOD onboarding, and posture checks that confirm a device meets security requirements before it is let on. For a small or mid-size business, that usually means ISE is the reason a visitor's laptop lands on a restricted guest network instead of the same segment as finance and payroll systems. With Change of Authorization configured, it is also how a former employee's device can be forced to reauthenticate and lose network access once IT disables the account, though an already-authorized session can otherwise persist until it times out or is manually revoked, and physical badge access is typically a separate system entirely. An unauthenticated bypass of the system making those admission decisions is a different order of severity than a single firewall or email gateway compromise. It does not just open one door; it hands an attacker control over the admission decisions for the entire network.

What the Vulnerability Is, and How Severe It Is

Cisco's advisory attributes the flaw to insufficient authentication controls on an ISE API endpoint, specifically the ise-kong REST management API gateway. An unauthenticated remote attacker can send a single crafted request to that endpoint to bypass the ISE web management interface entirely and gain unauthorized device access. The CVSS vector, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, spells out exactly how little an attacker needs: the flaw is reachable over the network, requires low attack complexity, needs no privileges and no user interaction, and a successful exploit gives full loss of confidentiality, integrity, and availability. Cisco's advisory adds, in its indicators-of-compromise guidance, that threat actors who successfully exploit the flaw may go on to obtain command execution with root privileges on the underlying device. Cisco's advisory lists ISE and ISE-PIC (Passive Identity Connector) versions 3.1, 3.2, 3.3, 3.4, and 3.5 as affected, "regardless of device configuration," meaning every deployment mode is exposed, not a specific feature combination. ISE 3.0 is old enough that Cisco is not patching it at all; those deployments need to migrate to 3.3, 3.4, or 3.5 to get a fix. The fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Cisco's advisory states there are no workarounds that address this vulnerability, so patching is the only real fix.

Key Recommendations

Start with an honest inventory. Confirm whether your organization, or a managed service provider acting on your behalf, runs on-premises Cisco ISE or ISE-PIC, and at what version.

If you do, apply the fixed patch for your branch on an emergency basis rather than folding it into a routine maintenance window. Cisco has confirmed there is no workaround, so the patch itself is the mitigation.

If you cannot patch immediately, restrict access now using infrastructure access control lists on the routers or firewalls upstream of ISE, limiting management and API-plane traffic to authorized admin jump hosts and API-management subnets only. This is a stopgap, not a substitute for patching.

If your ISE admin or management interface has been reachable from outside your trusted network at any point since before September 16, 2026, treat this as a possible compromise, not only a missing patch. Cisco's own confirmation of active exploitation means the window for "we just have not patched yet" and "we may already be compromised" has effectively closed for internet-exposed instances. Investigate authentication and admin activity logs for anything you cannot account for, and consider engaging incident response support if anything looks unfamiliar.

This is a separate, unrelated Cisco product from the two other Cisco advisories we covered this month: Secure Firewall Management Center (CVE-2026-20079, September 10) and Secure Email Gateway (CVE-2026-76461, September 15). Patching either of those does not touch this flaw, and an organization running ISE needs to check it independently.

What This Means for Your Access Control Obligations

For healthcare organizations whose Cisco ISE deployment is actually part of the access-control mechanism protecting systems that maintain electronic protected health information, rather than, for example, a guest-only network with no path to those systems, the HIPAA Security Rule's Technical Safeguards standard at 45 CFR 164.312(a)(1) requires covered entities and business associates to implement technical policies and procedures that allow access to electronic protected health information only to authorized persons or software, and the required implementation specification at 164.312(a)(2)(i) calls for unique user identification to track and control that access. Where ISE plays that role, it is functionally how that access control standard gets enforced at the network layer, and an unauthenticated bypass of ISE itself does not just create risk elsewhere; it undermines the access control safeguard directly, at the system responsible for enforcing it. HHS Office for Civil Rights guidance is explicit that identifying and remediating known, actively exploited vulnerabilities in systems that control access to networks handling protected health information falls within the ongoing risk analysis and risk management obligations at 45 CFR 164.308(a)(1)(ii)(A) and (B). CISA's September 19 window applies specifically to federal civilian agencies, but the underlying fact, a maximum-severity, unauthenticated, actively exploited bypass of an access control system with no available workaround, is exactly the kind of known risk those obligations already require a business to identify and act on wherever it applies.

If your organization operates Cisco ISE, or relies on a vendor who does, confirm your version and patch status today. Cyber One Solutions can help verify your exposure through our IT and security assessments, which inventory identity and access-control infrastructure like this one, and our managed cybersecurity service, whose vulnerability management program continuously scans for findings like this one, prioritizes them by real-world exploitability using data such as the CISA KEV catalog, and tracks remediation through to closure with patch validation scanning to confirm the fix actually took.

Sources