
Cisco is urging customers to patch immediately after confirming that attackers are actively exploiting CVE-2026-76460, a maximum-severity (CVSS 10.0) authentication bypass in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The flaw stems from insufficient authentication controls on an API endpoint — a remote attacker can send a crafted request and gain unauthorized access to the device, bypassing the web-based management interface entirely. No credentials are required.
Cisco’s Product Security Incident Response Team confirmed active exploitation in the wild and stated there are no workarounds. Organizations must upgrade to a fixed release. CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch within three days. Cisco separately disclosed a second max-severity ISE authentication bypass (CVE-2026-76423) and five other critical ISE flaws in the same advisory batch — none of those have been flagged as actively exploited yet, but all should be patched. Admins who detect suspicious activity should look for anomalous usernames in ISE access logs, re-image affected nodes, and restore from clean backups.
How to check if you’re affected
Affected versions include Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) releases prior to the fixed version listed in Cisco’s security advisory for CVE-2026-76460. If your organization runs ISE in any configuration, assume exposure and check for updates immediately. Cisco advises reviewing firewall and network logs for suspicious uploads or downloads to external IPs — attackers can remove evidence after gaining root command execution.
