Cisco has issued an urgent warning regarding a maximum-severity zero-day vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products, which is actively being exploited in the wild. The flaw, identified as CVE-2026-76460, allows remote attackers to bypass authentication by exploiting an API weakness, regardless of the system's configuration.
The vulnerability stems from insufficient authentication control on an API endpoint. An attacker can exploit this by sending a specially crafted request to the affected API, thereby gaining unauthorized access to the device and bypassing the web-based management interface. Cisco's Product Security Incident Response Team (PSIRT) confirmed active exploitation and strongly recommends immediate patching.
Cisco ISE serves as a centralized policy platform for IT administrators to manage network resource access for endpoints, users, and devices, often within Zero Trust security models. Given the critical role ISE plays in network security, the exploitation of this vulnerability poses a significant risk.
No workarounds are available, making the application of security updates the sole recommended course of action to protect networks from ongoing attacks. Cisco has released specific patch versions for various ISE and ISE-PIC releases: Release 3.1 requires Patch 12, Release 3.2 requires Patch 11, Release 3.3 requires Patch 12, Release 3.4 requires Patch 7, and Release 3.5 requires Patch 4.
In addition to providing fixed software releases, Cisco has shared indicators of compromise. Security teams are advised to examine `access.log` files on every node for suspicious usernames. If malicious activity is suspected, Cisco "strongly" recommends re-imaging the affected nodes and restoring them from backups. Administrators should also cross-reference firewall and network logs for any signs of suspicious activity, including downloads and uploads to or from external or malicious IP addresses, as attackers may attempt to remove evidence after achieving root privilege command execution.
The Cybersecurity and Infrastructure Security Agency (CISA) has also recognized the severity of CVE-2026-76460, adding it to its Known Exploited Vulnerabilities (KEV) Catalog. CISA has mandated that federal agencies patch their systems against this vulnerability within three days.
This zero-day follows a previous maximum-severity Cisco ISE zero-day (CVE-2025-20337) that was exploited in July 2025. That incident involved remote code execution attacks to deploy a custom "IdentityAuditAction" web shell, disguised as a legitimate ISE component. Over the past five years, CISA has identified 99 actively exploited security flaws in Cisco products, with seven of these being leveraged in ransomware attacks.
Coinciding with the CVE-2026-76460 patch, Cisco also addressed another maximum-severity authentication bypass flaw (CVE-2026-76423) and five other critical security issues (CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284) in Cisco ISE and ISE-PIC. However, these additional vulnerabilities have not yet been flagged as actively exploited.






