Networking giant Cisco has issued emergency patches to address a severely critical authentication bypass vulnerability impacting its Identity Services Engine (ISE) platform. The flaw, which has received the maximum possible severity score of 10.0 on the Common Vulnerability Scoring System (CVSS), is currently being actively exploited by malicious actors in the wild.
The security update marks the second time this week that Cisco has been forced to push emergency patches for actively exploited zero-day vulnerabilities across its enterprise product portfolio. Earlier in the week, the company scrambled to deploy fixes for a similarly critical zero-day security defect affecting its Secure Email Gateway appliances. The concentration of high-severity flaws highlights an increasingly aggressive landscape of targeted enterprise hardware and software exploitation.
The newly disclosed Cisco ISE vulnerability has been officially tracked as CVE-2026-76460. According to security advisories, the defect resides within a management-focused API endpoint embedded in the platform. This particular architectural flaw allows remote attackers to bypass the standard web-based management interface entirely. By transmitting specially crafted, malicious HTTP requests to the vulnerable endpoint, an unauthenticated attacker can successfully traverse security controls and instantly attain full root-level privileges on the underlying operating system of the target device.
Gaining root access via an unauthenticated remote vector grants malicious actors near-total control over the compromised appliance. Because Cisco ISE serves as a foundational component for enterprise network access control and policy enforcement, a breach of this magnitude could potentially allow attackers to manipulate authentication databases, bypass network segmentation rules, eavesdrop on internal administrative communications, or pivot deeper into sensitive corporate environments.
The vulnerability impacts both Cisco ISE and the Cisco ISE Passive Identity Connector (ISE-PIC) across virtually all software configurations. To remediate the threat, Cisco has released updated software packages spanning multiple maintenance branches. Depending on the major release deployed within an organization, administrators are urged to upgrade to version 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4.
The urgency of the patching cycle was underscored when the United States Cybersecurity and Infrastructure Security Agency (CISA) intervened. On Wednesday, CISA formally added CVE-2026-76460 to its heavily monitored Known Exploited Vulnerabilities (KEV) catalog. The inclusion mandates federal civilian executive branch agencies to secure their vulnerable instances within strict regulatory timeframes, while also serving as an urgent warning for private sector enterprises, critical infrastructure operators, and global organizations to prioritize immediate mitigation.
Mitigation and Incident Response
Organizations utilizing vulnerable instances of Cisco ISE and ISE-PIC face significant operational hurdles when conducting post-incident analysis and hunting for indicators of compromise. Because the vulnerability grants attackers unauthenticated root privileges, sophisticated threat actors frequently attempt to cover their tracks by wiping local logs and modifying system telemetry.
For IT and security operations teams seeking to determine whether their systems have already been breached, Cisco recommends initiating a forensic review of the access.log file stored on the affected appliances. Administrators should carefully comb through these logs to identify unfamiliar or suspicious usernames, which often serve as the primary indicator of unauthorized access.
However, because attackers who achieve root access can easily delete or tamper with local logs, security teams cannot rely solely on local device artifacts. Cisco advises organizations to expand their investigative scope to network and firewall logs situated upstream from the identity management devices. Analysts should look closely for anomalous network activity, including unauthorized file uploads and downloads initiated directly from the internal IP addresses of the ISE nodes.
For environments where malicious activity is discovered or strongly suspected, Cisco offers a stern remediation warning. The company notes that if an administrator suspects a node has been compromised, simple patching or superficial clean-up operations are insufficient. Instead, organizations are strongly advised to completely re-image the affected nodes from a trusted installation media source and subsequently restore system configurations from a verified, clean backup.
As an immediate defensive hardening measure, Cisco strongly recommends that network administrators implement infrastructure access control lists (iACLs). These specialized routing and firewall policies can restrict and limit the range of IP addresses permitted to send management and control traffic to the sensitive API endpoints of the affected devices, effectively narrowing the attack surface while patches are being scheduled and deployed.
More Critical Flaws Patched in Cisco ISE
The emergency patch release for CVE-2026-76460 was accompanied by a massive broader security audit of the platform. Cisco security engineers conducted a comprehensive review of the Cisco ISE and ISE-PIC architectures, unearthing and patching a staggering total of 21 critical vulnerabilities during the routine review cycle.
Among the newly discovered and fixed security defects are several remote code execution vulnerabilities, alongside additional API flaws that share the same underlying architectural weaknesses as CVE-2026-76460. Alongside the critical findings, the latest software releases address three high-severity flaws and 18 medium-severity vulnerabilities, representing one of the most substantial patch bundles ever issued for the identity enforcement platform.
The sweeping security updates follow a broader trend of intensive vulnerability patching across Cisco’s core infrastructure portfolio. Separately, the company recently rolled out patches targeting a series of critical and medium-severity flaws across its Cisco Secure Firewall Adaptive Security Appliance (ASA), Secure Firewall Threat Defense (FTD), and Secure Firewall Management Center (FMC) software lines.
Security researchers and intelligence analysts have noted that older vulnerabilities within these specific firewall and management platforms have been actively targeted by diverse threat actor groups throughout the year. In particular, threat campaigns have frequently leveraged legacy vulnerabilities such as CVE-2026-20079 and CVE-2026-20131 against the FMC software—flaws that were initially patched by the vendor earlier in March but continue to threaten organizations that have lagged behind on their emergency update schedules.