Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.
The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication.
"This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface."
The issue affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration. It has been addressed in the following versions -
- 3.1 - Fixed in 3.1 Patch 12
- 3.2 - Fixed in 3.2 Patch 11
- 3.3 - Fixed in 3.3 Patch 12
- 3.4 - Fixed in 3.4 Patch 7
- 3.51 - Fixed in 3.5 Patch 4
Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat. The company did not share any details on the nature of the attacks exploiting the flaw, or who is behind them.
As indicators of compromise (IoCs), Cisco is recommending that users review "access.log" and look for suspicious usernames. If the device is part of a distributed deployment, it's essential to review the logs of each node. It has provided the following command to detect unexpected usernames -
admin#show logging application ise-kong/access.log | include dummyuser
The presence of any entry in the command output likely points to malicious activity. If such activity is detected, users are advised to re-image the affected nodes and restore from configuration backup if needed.
"Upon successful exploitation of this vulnerability, threat actors may obtain command execution with root privileges," Cisco said. "Because of this level of access, evidence of exploitation and indicators of compromise may be removed or hidden by the threat actors."
Cisco also emphasized that there are no workarounds, but as a mitigation, customers can use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026, added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.
The disclosure comes merely days after Cisco said a critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway (CVE-2026-76461, CVSS score: 9.8) has come under active exploitation in the wild.
Besides CVE-2026-76460, Cisco has rolled out fixes for a number of critical security vulnerabilities spanning its product portfolio, some of which are hardening measures released as part of an ongoing review. Of the 77 new CVEs issued Wednesday, 41 affect ISE and 28 affect the Secure Firewall portfolio. A brief description of the flaws is below -
- CVE-2026-20176 (CVSS score: 9.9), CVE-2026-20211 (CVSS score: 9.1), CVE-2026-20307 (CVSS score: 9.1) - Multiple vulnerabilities in ISE that could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have valid administrative credentials.
- CVE-2026-76423 (CVSS score: 10.0), CVE-2026-76424, CVE-2026-76425, CVE-2026-76426, CVE-2026-76427, CVE-2026-76428 - Multiple vulnerabilities in ISE and Cisco ISE Passive Identity Connector (ISE-PIC) that could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on an affected device.
- CVE-2026-20282 (CVSS score: 9.1), CVE-2026-20283, CVE-2026-20284 - Multiple vulnerabilities in ISE that could allow an authenticated, remote attacker to conduct SQL injections, modify data, or execute arbitrary commands on the underlying operating system on an affected device.
- CVE-2026-20305 (CVSS score: 9.1), CVE-2026-20306 (CVSS score: 9.1) - Multiple vulnerabilities in ISE and ISE-PIC that could allow an authenticated, remote attacker to perform command injection attacks on an affected device and execute arbitrary commands as the root user. To exploit these vulnerabilities, the attacker must have valid administrative credentials.
- CVE-2026-20322 (CVSS score: 9.9), CVE-2026-20325 (CVSS score: 9.9), CVE-2026-20326 (CVSS score: 9.8), CVE-2026-20360, CVE-2026-20361, CVE-2026-76409 - Multiple vulnerabilities in Cisco Nexus Dashboard that could lead to command injection, authentication or authorization bypass, and information disclosure.
- CVE-2026-20130 (CVSS score: 10.0), CVE-2026-20192 (CVSS score: 10.0), CVE-2026-20194 (CVSS score: 9.1), CVE-2026-20234 (CVSS score: 9.9), CVE-2026-20237 (CVSS score: 9.9), CVE-2026-20287 - Multiple vulnerabilities in ISE and ISE-PIC that could lead to command injection, authentication or authorization bypass, and information disclosure.
- CVE-2026-20329 (CVSS score: 9.9), CVE-2026-20330 (CVSS score: 9.9), CVE-2026-20331 (CVSS score: 9.6), CVE-2026-20332 (CVSS score: 9.0), CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336 - Multiple vulnerabilities in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software that are grouped by CWE category, covering areas like improper handling of exceptional conditions, improper access control, improper adherence to coding standards, and improper control of a resource through its lifetime.
- CVE-2026-76412, CVE-2026-76413, CVE-2026-76420 (CVSS score: 9.0) - Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software that could allow a remote attacker to gain root access and perform session forgery or session impersonation.
- CVE-2026-20324 (CVSS score: 9.9) - A vulnerability in the sftunnel inter-device communication protocol of FMC Software that could allow an authenticated, remote attacker to execute arbitrary commands as root.
- CVE-2026-20340, CVE-2026-20341 (CVSS score: 9.1), CVE-2026-20342, CVE-2026-20343, CVE-2026-20344 - Multiple vulnerabilities in FMC Software that could allow a remote attacker to gain root access, download sensitive files, perform a SQL injection attack, or cause a denial-of-service (DoS) condition.
- CVE-2026-20242 (CVSS score: 9.8) - A vulnerability in the External Database Access feature of FMC Software that could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device.
- CVE-2026-20353 (CVSS score: 9.8), CVE-2026-76440 (CVSS score: 9.8), CVE-2026-76441 (CVSS score: 9.8), CVE-2026-76442 (CVSS score: 9.8), CVE-2026-76443 - Multiple vulnerabilities in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager that could lead to path traversal, authentication or authorization bypass, uncontrolled resource consumption, and command injection.
Although none of these vulnerabilities have been listed as actively exploited, it's essential that users apply the fixes as soon as possible given the criticality of the weaknesses and the fact that they offer multiple pathways for arbitrary code execution.




