Executive Summary

    On September 16th, 2026, Cisco disclosed a critical vulnerability in Identity Services Engine (ISE) and confirmed it is under active exploitation. Tracked as CVE-2026-76460, the flaw stems from insufficient authentication control on an API endpoint. Cisco states that successful exploitation can give an attacker command execution with root privileges. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog the same day.

    ISE is a centralized network access control and policy platform. It authenticates users, profiles devices, evaluates security posture, and controls access to wired, wireless, and VPN networks. An attacker with root on an ISE deployment can read and alter the identity and policy data it holds. Cisco has released fixed software.

    Given confirmed exploitation, root-level impact, and the position ISE occupies in enterprise identity infrastructure, Beazley Security recommends affected organizations apply available fixes immediately and conduct a thorough review for any signs of compromise.

    Affected Systems or Products

    Cisco ISE and ISE Passive Identity Connector (ISE-PIC) releases 3.0 through 3.5 are affected, regardless of device configuration.

    Product Release

    Affected Versions

    First Fixed Release

    Cisco ISE / ISE-PIC 3.0

    All

    No fix, migrate to a supported release

    Cisco ISE / ISE-PIC 3.1

    Before 3.1 Patch 12

    3.1 Patch 12

    Cisco ISE / ISE-PIC 3.2

    Before 3.2 Patch 11

    3.2 Patch 11

    Cisco ISE / ISE-PIC 3.3

    Before 3.3 Patch 12

    3.3 Patch 12

    Cisco ISE / ISE-PIC 3.4

    Before 3.4 Patch 7

    3.4 Patch 7

    Cisco ISE / ISE-PIC 3.5

    Before 3.5 Patch 4

    3.5 Patch 4

    Mitigations / Workarounds

    Cisco states there are no workarounds that address this vulnerability, so patching is the only remediation. Release 3.0 is no longer maintained, and releases 3.1 and 3.2 receive critical fixes only, so organizations running those trains should plan a migration to 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4.

    Where an upgrade cannot happen immediately, the following steps reduce exposure:

    • Apply infrastructure access control lists (iACLs) that permit only required management and control plane traffic destined for ISE nodes, blocking untrusted networks from reaching the management interface.

    • Restrict management interface reachability to administrative networks, and confirm no ISE node is exposed to the internet.

    • If exploitation is suspected on a node, re-image that node and restore from a configuration backup rather than attempting to clean it in place.

    Patches

    Cisco has released fixed software for all supported versions. Customers should download the applicable patch through their normal Cisco software update channel, and details are available in the official Cisco security advisory. Release 3.0 does not receive a fix and requires migration to a supported release.

    Indicators of Compromise

    On September 16th, 2026, CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. Cisco has confirmed exploitation independently but has not published attacker infrastructure or campaign details.

    Cisco recommends review of the the ISE access log for unexpected or suspicious usernames, which is the primary artifact of an exploitation attempt. Defenders can review the ise-kong access log, reachable from the admin CLI with show logging application ise-kong/access.log. Any unexpected username in that output warrants investigation.

    Technical Details

    Cisco has released limited technical detail and no public proof-of-concept exploit is known at the time of publication. The vulnerability is an authentication bypass caused by insufficient authentication control on an ISE API endpoint. A crafted request to that endpoint is served without the authentication the interface is supposed to require, which hands an unauthenticated attacker the access of a legitimate management user.

    The flaw is reachable regardless of device configuration where the API is exposed, so no optional feature or specific deployment mode is needed to trigger it. The resulting access can escalate to command execution with root privileges on the underlying operating system.

    How Beazley Security is responding

    Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.

    We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.

    If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team.