Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Cisco warns of critical zero-day ISE auth bypass vulnerability (CVSS 10.0) actively exploited.
Summary
Cisco has issued a critical alert for a zero-day vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) and ISE Passive Identity Connector, which has a CVSS score of 10.0 and is being actively exploited. The flaw allows unauthenticated remote attackers to bypass authentication and gain unauthorized access, potentially leading to root privilege command execution. Cisco urges customers to upgrade to patched versions immediately, as there are no workarounds.
Full text
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Ravie LakshmananSep 17, 2026Vulnerability / Web Security Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface." The issue affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration. It has been addressed in the following versions - 3.1 - Fixed in 3.1 Patch 12 3.2 - Fixed in 3.2 Patch 11 3.3 - Fixed in 3.3 Patch 12 3.4 - Fixed in 3.4 Patch 7 3.51 - Fixed in 3.5 Patch 4 Cisco said it's "aware of active exploitation of this vulnerability," urging customers to upgrade to a fixed software release to counter the threat. The company did not share any details on the nature of the attacks exploiting the flaw, or who is behind them. As indicators of compromise (IoCs), Cisco is recommending that users review "access.log" and look for suspicious usernames. If the device is part of a distributed deployment, it's essential to review the logs of each node. It has provided the following command to detect unexpected usernames - admin#show logging application ise-kong/access.log | include dummyuser The presence of any entry in the command output likely points to malicious activity. If such activity is detected, users are advised to re-image the affected nodes and restore from configuration backup if needed. "Upon successful exploitation of this vulnerability, threat actors may obtain command execution with root privileges," Cisco said. "Because of this level of access, evidence of exploitation and indicators of compromise may be removed or hidden by the threat actors." Cisco also emphasized that there are no workarounds, but as a mitigation, customers can use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device. The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on September 16, 2026, added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026. The disclosure comes merely days after Cisco said a critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway (CVE-2026-76461, CVSS score: 9.8) has come under active exploitation in the wild. Besides CVE-2026-76460, Cisco has rolled out fixes for a number of critical security vulnerabilities spanning its product portfolio, some of which are hardening measures released as part of an ongoing review. Of the 77 new CVEs issued Wednesday, 41 affect ISE and 28 affect the Secure Firewall portfolio. A brief description of the flaws is below - CVE-2026-20176 (CVSS score: 9.9), CVE-2026-20211 (CVSS score: 9.1), CVE-2026-20307 (CVSS score: 9.1) - Multiple vulnerabilities in ISE that could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have valid administrative credentials. CVE-2026-76423 (CVSS score: 10.0), CVE-2026-76424, CVE-2026-76425, CVE-2026-76426, CVE-2026-76427, CVE-2026-76428 - Multiple vulnerabilities in ISE and Cisco ISE Passive Identity Connector (ISE-PIC) that could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on an affected device. CVE-2026-20282 (CVSS score: 9.1), CVE-2026-20283, CVE-2026-20284 - Multiple vulnerabilities in ISE that could allow an authenticated, remote attacker to conduct SQL injections, modify data, or execute arbitrary commands on the underlying operating system on an affected device. CVE-2026-20305 (CVSS score: 9.1), CVE-2026-20306 (CVSS score: 9.1) - Multiple vulnerabilities in ISE and ISE-PIC that could allow an authenticated, remote attacker to perform command injection attacks on an affected device and execute arbitrary commands as the root user. To exploit these vulnerabilities, the attacker must have valid administrative credentials. CVE-2026-20322 (CVSS score: 9.9), CVE-2026-20325 (CVSS score: 9.9), CVE-2026-20326 (CVSS score: 9.8), CVE-2026-20360, CVE-2026-20361, CVE-2026-76409 - Multiple vulnerabilities in Cisco Nexus Dashboard that could lead to command injection, authentication or authorization bypass, and information disclosure. CVE-2026-20130 (CVSS score: 10.0), CVE-2026-20192 (CVSS score: 10.0), CVE-2026-20194 (CVSS score: 9.1), CVE-2026-20234 (CVSS score: 9.9), CVE-2026-20237 (CVSS score: 9.9), CVE-2026-20287 - Multiple vulnerabilities in ISE and ISE-PIC that could lead to command injection, authentication or authorization bypass, and information disclosure. CVE-2026-20329 (CVSS score: 9.9), CVE-2026-20330 (CVSS score: 9.9), CVE-2026-20331 (CVSS score: 9.6), CVE-2026-20332 (CVSS score: 9.0), CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336 - Multiple vulnerabilities in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software that are grouped by CWE category, covering areas like improper handling of exceptional conditions, improper access control, improper adherence to coding standards, and improper control of a resource through its lifetime. CVE-2026-76412, CVE-2026-76413, CVE-2026-76420 (CVSS score: 9.0) - Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software that could allow a remote attacker to gain root access and perform session forgery or session impersonation. CVE-2026-20324 (CVSS score: 9.9) - A vulnerability in the sftunnel inter-device communication protocol of FMC Software that could allow an authenticated, remote attacker to execute arbitrary commands as root. CVE-2026-20340, CVE-2026-20341 (CVSS score: 9.1), CVE-2026-20342, CVE-2026-20343, CVE-2026-20344 - Multiple vulnerabilities in FMC Software that could allow a remote attacker to gain root access, download sensitive files, perform a SQL injection attack, or cause a denial-of-service (DoS) condition. CVE-2026-20242 (CVSS score: 9.8) - A vulnerability in the External Database Access feature of FMC Software that could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. CVE-2026-20353 (CVSS score: 9.8), CVE-2026-76440 (CVSS score: 9.8), CVE-2026-76441 (CVSS score: 9.8), CVE-2026-76442 (CVSS score: 9.8), CVE-2026-76443 - Multiple vulnerabilities in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager that could lead to path traversal, authentication or authorization bypass, uncontrolled resource consumption, and command injection. Although none of these vulnerabilities have been listed as actively exploited, it's essential that users apply the fixes as soon as possible given the criticality of the weaknesses and the fact that they offer multiple pathways for arbitrary code execution. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE cisco, Identity Security, network security, Vulnerability, Web Security ⚡ Top Stories This Week OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Claude Used to Automate E
Indicators of Compromise
- cve — CVE-2026-76460
- cve — CVE-2026-76423
- cve — CVE-2026-20176
- cve — CVE-2026-20211
- cve — CVE-2026-20307
- cve — CVE-2026-76461