Cisco warns of max severity ISE zero-day exploited in attacks

A Critical Cisco Vulnerability is Being Actively Exploited, Posing a Significant Threat to Networks Worldwide

Cisco has issued an urgent warning about a maximum-severity vulnerability in its Identity Services Engine (ISE) platform, which is being exploited by attackers in real-world attacks. The security flaw, tracked as CVE-2026-76460, allows remote attackers to bypass authentication and gain unauthorized access to network resources.

The affected platform, Cisco ISE, is used by IT administrators to manage endpoints, users, and device access to network resources, often enforcing Zero Trust security models. This centralized policy platform is a critical component of many organizations’ networks, making the vulnerability particularly concerning. The flaw resides in an API endpoint, which can be exploited by sending a crafted request to bypass authentication controls.

“This vulnerability is due to insufficient authentication control on an API endpoint,” Cisco explained in its advisory. “An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint… A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.”

Cisco’s Product Security Incident Response Team (PSIRT) has confirmed that the vulnerability is actively being exploited, and the company strongly recommends that customers upgrade to a fixed software release as soon as possible. Unfortunately, there are no workarounds available to mitigate the risk.

The affected versions of Cisco ISE include 3.1, 3.2, 3.3, 3.4, and 3.5, with specific patches required for each version. Administrators should apply these updates immediately to prevent ongoing attacks.

In addition to patching, Cisco has provided indicators of compromise (IOCs) that security teams can use to detect suspicious activity. These IOCs include suspicious usernames in access.log files on every node and signs of malicious activity in firewall and network logs.

The attack may not be limited to just the exploitation of the vulnerability itself; attackers may also attempt to cover their tracks by removing evidence of exploitation after obtaining command execution with root privileges.

This is not an isolated incident – Cisco has patched a total of six maximum-severity authentication bypass flaws in its ISE platform over the past year, including this latest one. The Cybersecurity and Infrastructure Security Agency (CISA) has also added CVE-2026-76460 to its Known Exploited Vulnerabilities Catalog, requiring federal agencies to patch their systems within three days.

This vulnerability serves as a reminder of the importance of staying up-to-date with security patches and updates for critical infrastructure components like Cisco ISE. With attackers increasingly exploiting zero-day vulnerabilities, it’s essential for organizations to prioritize proactive security measures, including regular patching and threat intelligence monitoring.

To protect your network from this vulnerability, apply the recommended software updates as soon as possible, monitor your systems closely for signs of suspicious activity, and consider implementing additional security measures, such as intrusion detection and prevention systems. By taking these steps, you can help prevent unauthorized access to your network resources and mitigate the risk of a successful attack.


Source: Bleeping Computer — 2026-09-17