Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
North Korean IT workers exploit AI, remote tools to fake interviews
September 17, 2026
Critical Docker Sandbox Vulnerabilities Let Guests Escape microVMs
September 17, 2026
Critical Cisco ISE 0-Day Vulnerability Exploited in Attacks
September 17, 2026
Home/Vulnerabilities/Critical Cisco ISE 0-Day Vulnerability Exploited in Attacks
Vulnerabilities

Critical Cisco ISE 0-Day Vulnerability Exploited in Attacks

Key Takeaways Cisco has issued an urgent advisory for a critical zero-day vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The flaw,...

Sarah simpson
Sarah simpson
September 17, 2026 4 Min Read
2 0

Key Takeaways

  • Cisco has issued an urgent advisory for a critical zero-day vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC).
  • The flaw, rated with a CVSS score of 10.0, is actively being exploited and allows unauthenticated remote attackers to bypass authentication and achieve root-level command execution.
  • The vulnerability affects all supported Cisco ISE and ISE-PIC versions, as well as the end-of-life ISE 3.0.
  • Patches are available for supported versions, and immediate updates are the primary remediation.

Cisco ISE Zero-Day Under Active Exploitation

Cisco has released a critical security advisory warning of a zero-day vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products, which is currently being exploited in the wild. The flaw, identified as CVE-2026-76460, carries the highest possible CVSS score of 10.0, indicating extreme severity and ease of exploitation.

Table Of Content

  • Key Takeaways
  • Cisco ISE Zero-Day Under Active Exploitation
  • Impact and Root-Level Access
  • Affected Versions and Patches
  • Mitigation and Detection Strategies
  • What You Should Do

According to Cisco’s Product Security Incident Response Team, the vulnerability allows an unauthenticated remote attacker to bypass authentication mechanisms on affected systems. This critical weakness stems from insufficient authentication controls on a specific API endpoint within Cisco ISE, enabling threat actors to gain unauthorized access by sending a specially crafted request.

Impact and Root-Level Access

Cisco ISE is a foundational component for many enterprises, managing network access, enforcing security policies, and authenticating users and devices across diverse environments. A successful compromise of an ISE instance provides attackers with a high-value entry point into an organization’s core identity and network management infrastructure.

The vendor has confirmed that successful exploitation can lead to command execution with root privileges. Such elevated access grants attackers complete control over the compromised ISE node, enabling them to modify configurations, deploy malicious tools, establish persistence, steal credentials, or leverage the appliance as a pivot point for lateral movement within the network.

Affected Versions and Patches

The vulnerability impacts all versions of Cisco ISE and Cisco ISE-PIC, irrespective of their specific configuration. This includes Cisco ISE Software Release 3.0, which has reached its end-of-software-maintenance. Organizations still running version 3.0 are strongly advised to migrate to a currently supported release that incorporates the necessary security fixes.

Cisco has released patches for all supported platform versions. The patched releases are:

  • ISE 3.1 Patch 12
  • ISE 3.2 Patch 11
  • ISE 3.3 Patch 12
  • ISE 3.4 Patch 7
  • ISE 3.5 Patch 4
  • Administrators must identify their deployed version and upgrade to the corresponding fixed release without delay. Cisco has stated that no workaround exists, making software updates the primary and most effective remediation.

    Mitigation and Detection Strategies

    For organizations unable to apply patches immediately, Cisco recommends implementing infrastructure access control lists (iACLs) to restrict management and control-plane traffic to vulnerable devices. This temporary measure aims to limit exposure by ensuring that only essential and trusted systems can communicate with Cisco ISE management interfaces. However, Cisco emphasizes that iACLs do not address the underlying vulnerability and are not a substitute for patching.

    Organizations should also actively investigate their systems for any signs of exploitation. Cisco advised reviewing the access.log file for suspicious usernames or unusual API activity. In distributed ISE environments, it is crucial to examine every node, as attackers may target any accessible instance. An example command for reviewing suspicious login events is show logging application ise-kong/access.log | include dummyuser.

    For deeper forensic analysis, security teams should enable debug logs and collect support bundles to access additional API gateway logs. Cisco cautions that evidence on a compromised device might be incomplete, as attackers with root privileges could potentially remove or obscure forensic artifacts. Therefore, reviewing firewall and network logs external to the appliance is also critical. Unexplained uploads from an ISE node to external IP addresses, suspicious downloads, or unexpected outbound connections could all indicate a compromise.

    The vulnerability was discovered by Cisco while resolving a Cisco Technical Assistance Center support case, highlighting the importance of proactive monitoring and reporting.

    What You Should Do

    • Patch Immediately: Upgrade all affected Cisco ISE and ISE-PIC installations to the latest patched versions (ISE 3.1 Patch 12, ISE 3.2 Patch 11, ISE 3.3 Patch 12, ISE 3.4 Patch 7, and ISE 3.5 Patch 4).
    • Migrate EOL Versions: If using Cisco ISE 3.0, migrate to a supported, patched release as soon as possible.
    • Implement iACLs (Temporary): If immediate patching is not feasible, deploy infrastructure access control lists (iACLs) to limit management and control-plane traffic to only essential and trusted systems. Remember, this is a temporary mitigation.
    • Monitor Logs: Review access.log files on all ISE nodes for suspicious usernames or unexpected API activity. Use commands like show logging application ise-kong/access.log | include dummyuser for specific event review.
    • Enable Debug Logs: For enhanced visibility, enable debug logs and collect support bundles to capture comprehensive API gateway logs.
    • Examine Network Traffic: Monitor firewall and network logs for unusual outbound connections, suspicious downloads, or unexpected uploads originating from ISE nodes.
    • Reimage and Restore: If a compromise is suspected or confirmed, reimage affected ISE nodes and restore configurations from known-good backups.

    Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

    Tags:

    AttackCVEExploitPatchSecurityThreatVulnerabilityzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Kubernetes Flaw Exposes Workload Identities

Next Post

Critical Docker Sandbox Vulnerabilities Let Guests Escape microVMs

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
BlackHatSect0r AI Agent Automates Attacks, Harvests 16,834 Credentials
September 17, 2026
APT36 Uses USB Malware to Breach Air-Gapped Government Networks
September 17, 2026
AWS Data Loss: War Damage in Ukraine Permanently Deletes Cloud Data
September 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us