Skip to content

Security3 publishers2 min readPublished Updated

Cisco patches an ISE authentication bypass attackers used before the fix existed

CVE-2026-76460 scores a CVSS 10.0, affects Cisco ISE and ISE-PIC in every configuration, and has no workaround. CISA added it to the KEV catalog the day the patches shipped and gave federal agencies three days.

The Watch · Security desk

Illustration accompanying Cisco patches an ISE authentication bypass attackers used before the fix existed

What happened

  • Cisco released urgent patches on Wednesday for a critical authentication bypass in Identity Services Engine that had already been exploited in the wild as a zero-day.
  • Both ISE and ISE-PIC are affected regardless of device configuration, and no workaround exists, though infrastructure access control lists restricting traffic to the appliance prevent remote exploitation.
  • CISA added the zero-day to its Known Exploited Vulnerabilities catalog on Wednesday, giving federal agencies three days to patch under BOD 26-04.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Configuration hardening removes nothing from scope: every ISE and ISE-PIC node whose API can receive packets is reachable until it is patched or fronted by an access list.
  • decision Operators have to decide between patch-in-place and rebuild using logs held off the appliance, because the on-device record is editable by anyone who already has root.
  • cost Where suspicion of malicious activity exists, the work Cisco recommends is a full re-image and configuration restore of each affected node, a larger job than the upgrade.
  • precedent A same-day KEV listing with a three-day clock puts federal agencies on an emergency change schedule for an identity appliance, and everyone outside that scope faces the same active exploitation with no deadline attached.

Root is what makes the log check uncertain. Cisco tells administrators to review access.log for suspicious usernames on every node in a distributed deployment [10]. It also says successful exploitation can execute commands with root privileges, and that root lets an attacker hide or delete indicators of compromise [12]. The evidence file sits on the machine the intruder controls, so an empty access.log does not establish that a node is clean [16]. Cisco's advisory sends administrators off the appliance for corroboration: network logs and firewall logs, checked for unexpected uploads and downloads [13].

"The presence of any entry in the output may indicate malicious activity. This should be done on every node in the deployment. If malicious activity is suspected, it is strongly recommended to re-image the affected nodes and restore from configuration backup if needed," Cisco said in its advisory [11]. Suspicion alone is enough to trigger the re-image.

The upgrade is a branch-by-branch exercise. Cisco lists the fixed builds as ISE and ISE-PIC 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11, and 3.1 Patch 12 [6], one target build for each of the five supported branches [15]. An estate with nodes pinned to an older branch for compatibility has to be matched node by node.

The bypass itself is an API endpoint that does not apply sufficient authentication controls, reached by sending crafted requests that get around the web-based management interface [2][3]. Both ISE and ISE-PIC are affected however the device is set up [4].

"The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability," the company said in the advisory [7]. Cisco has not shared any information on who is behind the attacks [8]. SecurityWeek, which reported the advisory, notes that cybercriminals and state-sponsored threat actors regularly target vulnerabilities in Cisco products [9], and ran the ISE story alongside its own coverage of a root remote code execution zero-day in Cisco Secure Email Gateway also under active exploitation [17].

What to watch

  • Any attribution of the ISE exploitation to a named crew or state-sponsored group, from Cisco or a third-party responder.
  • Additional indicators of compromise beyond suspicious access.log usernames, which would give defenders a check the attacker cannot edit.
  • Whether CISA's KEV entry is updated with exploitation detail or a revised due date for federal agencies.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories