Critical Cisco ISE 0-Day Vulnerability Exploited in Attacks
Key Takeaways Cisco has issued an urgent advisory for a critical zero-day vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The flaw,...
Key Takeaways
- Cisco has issued an urgent advisory for a critical zero-day vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC).
- The flaw, rated with a CVSS score of 10.0, is actively being exploited and allows unauthenticated remote attackers to bypass authentication and achieve root-level command execution.
- The vulnerability affects all supported Cisco ISE and ISE-PIC versions, as well as the end-of-life ISE 3.0.
- Patches are available for supported versions, and immediate updates are the primary remediation.
Cisco ISE Zero-Day Under Active Exploitation
Cisco has released a critical security advisory warning of a zero-day vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products, which is currently being exploited in the wild. The flaw, identified as CVE-2026-76460, carries the highest possible CVSS score of 10.0, indicating extreme severity and ease of exploitation.
Table Of Content
According to Cisco’s Product Security Incident Response Team, the vulnerability allows an unauthenticated remote attacker to bypass authentication mechanisms on affected systems. This critical weakness stems from insufficient authentication controls on a specific API endpoint within Cisco ISE, enabling threat actors to gain unauthorized access by sending a specially crafted request.
Impact and Root-Level Access
Cisco ISE is a foundational component for many enterprises, managing network access, enforcing security policies, and authenticating users and devices across diverse environments. A successful compromise of an ISE instance provides attackers with a high-value entry point into an organization’s core identity and network management infrastructure.
The vendor has confirmed that successful exploitation can lead to command execution with root privileges. Such elevated access grants attackers complete control over the compromised ISE node, enabling them to modify configurations, deploy malicious tools, establish persistence, steal credentials, or leverage the appliance as a pivot point for lateral movement within the network.
Affected Versions and Patches
The vulnerability impacts all versions of Cisco ISE and Cisco ISE-PIC, irrespective of their specific configuration. This includes Cisco ISE Software Release 3.0, which has reached its end-of-software-maintenance. Organizations still running version 3.0 are strongly advised to migrate to a currently supported release that incorporates the necessary security fixes.
Cisco has released patches for all supported platform versions. The patched releases are:
- ISE 3.1 Patch 12
- ISE 3.2 Patch 11
- ISE 3.3 Patch 12
- ISE 3.4 Patch 7
- ISE 3.5 Patch 4
- Patch Immediately: Upgrade all affected Cisco ISE and ISE-PIC installations to the latest patched versions (ISE 3.1 Patch 12, ISE 3.2 Patch 11, ISE 3.3 Patch 12, ISE 3.4 Patch 7, and ISE 3.5 Patch 4).
- Migrate EOL Versions: If using Cisco ISE 3.0, migrate to a supported, patched release as soon as possible.
- Implement iACLs (Temporary): If immediate patching is not feasible, deploy infrastructure access control lists (iACLs) to limit management and control-plane traffic to only essential and trusted systems. Remember, this is a temporary mitigation.
- Monitor Logs: Review
access.logfiles on all ISE nodes for suspicious usernames or unexpected API activity. Use commands likeshow logging application ise-kong/access.log | include dummyuserfor specific event review. - Enable Debug Logs: For enhanced visibility, enable debug logs and collect support bundles to capture comprehensive API gateway logs.
- Examine Network Traffic: Monitor firewall and network logs for unusual outbound connections, suspicious downloads, or unexpected uploads originating from ISE nodes.
- Reimage and Restore: If a compromise is suspected or confirmed, reimage affected ISE nodes and restore configurations from known-good backups.
Administrators must identify their deployed version and upgrade to the corresponding fixed release without delay. Cisco has stated that no workaround exists, making software updates the primary and most effective remediation.
Mitigation and Detection Strategies
For organizations unable to apply patches immediately, Cisco recommends implementing infrastructure access control lists (iACLs) to restrict management and control-plane traffic to vulnerable devices. This temporary measure aims to limit exposure by ensuring that only essential and trusted systems can communicate with Cisco ISE management interfaces. However, Cisco emphasizes that iACLs do not address the underlying vulnerability and are not a substitute for patching.
Organizations should also actively investigate their systems for any signs of exploitation. Cisco advised reviewing the access.log file for suspicious usernames or unusual API activity. In distributed ISE environments, it is crucial to examine every node, as attackers may target any accessible instance. An example command for reviewing suspicious login events is show logging application ise-kong/access.log | include dummyuser.
For deeper forensic analysis, security teams should enable debug logs and collect support bundles to access additional API gateway logs. Cisco cautions that evidence on a compromised device might be incomplete, as attackers with root privileges could potentially remove or obscure forensic artifacts. Therefore, reviewing firewall and network logs external to the appliance is also critical. Unexplained uploads from an ISE node to external IP addresses, suspicious downloads, or unexpected outbound connections could all indicate a compromise.
The vulnerability was discovered by Cisco while resolving a Cisco Technical Assistance Center support case, highlighting the importance of proactive monitoring and reporting.
What You Should Do
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.