Cisco patches actively exploited authentication bypass in Identity Services Engine

Cisco released security updates for a maximum-severity vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector, tracked as CVE-2026-76460, which allows remote attackers to bypass authentication via a crafted API request. The company confirmed active exploitation and said no workarounds exist, urging customers to upgrade to fixed releases. Cisco also provided indicators of compromise and recommended re-imaging affected nodes if malicious activity is suspected.
Cisco’s advisory covers multiple ISE and ISE-PIC releases, with patches ranging from 3.1 Patch 12 up to 3.5 Patch 4. The company has urged administrators to inspect access.log files for unusual usernames and to review firewall logs for anomalous external connections, since attackers may erase traces after gaining root-level command execution. Re-imaging affected nodes from clean backups is strongly recommended if compromise is suspected. This incident follows a July 2025 Cisco ISE zero-day that was used to deploy a disguised web shell, and CISA has now added the current flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies a three-day remediation deadline.
This vulnerability could have significant consequences for enterprises and government agencies that rely on Cisco ISE for network access control and Zero Trust enforcement. A successful authentication bypass may allow attackers to reach sensitive internal systems, potentially disrupting operations or exfiltrating data. Because the flaw is already being exploited, organizations without patching capacity may face heightened risk, and smaller IT teams could struggle to respond quickly. The incident may also prompt broader scrutiny of network infrastructure vendors' patch timelines and disclosure practices.