Cisco has issued fixes for CVE-2026-76460, a CVSS 10.0 authentication bypass in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) now under active exploitation. Remote attackers without credentials can issue specially formed calls to an exposed API to reach management functionality. CISA placed the flaw in its Known Exploited Vulnerabilities (KEV) Catalog on Wednesday with a three-day federal remediation deadline, and Cisco states no workarounds exist.
Affected software and fixed releases
The issue affects Cisco Identity Services Engine (ISE) Software and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of configuration. Details are documented in the NVD detail and in Cisco advisories cisco-sa-ISE-ABP-VNSW7Tn5 and cisco-sa-notice-jfxK98ZP.
Vulnerable branches and corrections summarized in a community analysis (gist analysis, published 2026-09-16, full report) are:
- Cisco Identity Services Engine (ISE) Software : 3.1.0 <= Patch 11 (Fixed in: 3.1.0 Patch 12 )
- Cisco Identity Services Engine (ISE) Software : 3.2.0 <= Patch 10 (Fixed in: 3.2.0 Patch 11 )
- Cisco Identity Services Engine (ISE) Software : 3.3.0 <= Patch 11 (Fixed in: 3.3.0 Patch 12 )
- Cisco Identity Services Engine (ISE) Software : 3.4.0 <= Patch 6 (Fixed in: 3.4.0 Patch 7 )
- Cisco Identity Services Engine (ISE) Software : 3.5.0 <= Patch 3 (Fixed in: 3.5.0 Patch 4 )
ISE supplies central control over identities, endpoints, and network access decisions, commonly deployed as part of Zero Trust designs. Cisco’s Product Security Incident Response Team (PSIRT) confirms active exploitation of CVE-2026-76460 and urges upgrade to a fixed release.
How the attack works
Cisco attributes the flaw to a missing authentication check on an API route. An unauthenticated remote party can submit a manipulated API call and thereby reach device functions without passing through the web-based management login.
A successful request yields unauthorized access to the affected appliance. Cisco cautions that intruders gaining command execution with root privileges may delete traces afterward, complicating forensic review.
Proof of concept
No vendor exploit is published, but an educational lab models the pattern in CVE-2026-76460 lab. The project description states:
This project demonstrates a mock authentication-bypass scenario inspired by CVE-2026-76460. The lab is intentionally educational and safe: it is a local Flask API that simulates the vulnerable and patched behavior without targeting real systems.
It further notes the application shows how a privileged management API can be exposed without authentication controls, and how a secure implementation blocks unauthenticated access.
The lab flow is:
flowchart LR
Client[Local client or test harness] --> Entry[app.py]
Entry --> Factory[security_lab.factory]
Factory --> Mode{Lab mode}
Mode -->|vulnerable| Open[Management users endpoint\nallows anonymous access]
Mode -->|secure| Bearer[Bearer token validation]
Mode -->|secure-strict| Admin[Bearer token + admin role]
Bearer --> Result[200 or 401 response]
Admin --> Result2[200, 401, or 403 response]
Open --> Result3[200 response with warning]
Factory --> Audit[Audit logger]
Audit --> Log[audit.log]
Repository layout is:
.
├── app.py # entry point for the local lab
├── build.sh # creates the venv, installs dependencies, and runs checks
├── run.sh # starts the vulnerable app locally
├── pyproject.toml # project metadata and tool configuration
├── gunicorn.conf.py # deployment configuration for a production-style server
├── src/
│ └── security_lab/
│ ├── __init__.py
│ ├── config.py # lab settings and valid tokens
│ ├── audit.py # file-based audit logger
│ └── factory.py # Flask routes and auth logic
├── tests/
│ └── test_api.py # regression tests for vulnerable and secure modes
├── exploit.py # proof-of-concept route attack script
├── pentest_harness.py # CLI verification helper
├── BUILD_GUIDE.md #
In that lab, app.py loads security_lab.factory, which selects vulnerable, secure, or secure-strict handling. Vulnerable mode returns 200 response with warning for anonymous calls to the management users endpoint. Secure modes enforce bearer validation, with strict mode also checking admin role and returning 200 or 401 response or 200, 401, or 403 response. Activity is written to audit.log via exploit.py and pentest_harness.py helpers and tests/test_api.py regression checks.
Detection and mitigation
Cisco reports no workarounds; installing the patched releases is the sole recommended remediation. CISA action is tracked in CISA alert 2026-09-16 and KEV entry for CVE-2026-76460, requiring federal agencies to patch within three days.
For compromise hunting, Cisco advises:
- Review
access.logfiles on every node for unfamiliar usernames - If malicious activity is suspected, strongly consider re-imaging nodes and restoring them from backups
- Correlate firewall and network logs for unusual downloads and uploads involving external or malicious IP addresses, since local evidence may have been wiped after root-level access
General hardening noted in public summaries includes restricting management interfaces to trusted administrative subnets and maintaining continuous monitoring for unauthenticated access to administrative paths.
Related flaws and prior activity
Separately, Cisco patched a second maximum-severity authentication bypass, CVE-2026-76423, plus five other critical issues tracked as CVE-2026-76460, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284 in Cisco ISE and Cisco ISE-PIC. Those additional items have not been flagged as actively exploited.
Context includes July 2025 exploitation of Cisco ISE zero-day CVE-2025-20337 with a maximum severity score in remote code execution attacks to install a custom IdentityAuditAction web shell masquerading as a legitimate ISE component. Over the last five years, CISA designated 99 flaws in Cisco products as actively exploited, including seven abused in ransomware attacks.
Technical background
General explanation of this vulnerability class, not specifics of this incident. Authentication bypasses occur when a privileged handler is reachable without verifying caller identity, for example a management route that forgets a decorator or middleware check. A generic illustration of the pattern:
# GENERIC illustration only - not CVE-2026-76460
@app.route('/api/admin/users')
def list_users():
# missing: verify Authorization header / session role
return jsonify(get_all_users())
Defenders typically verify with generic checks such as inspecting access logs for anonymous hits to admin paths:
# GENERIC example - adapt paths to local environment
grep -i "401\|unauthenticated\|admin" /var/log/app/access.log | tail -n 100