Cisco Rushes Patches as Actively Exploited ISE Zero-Day Bypasses Authentication

Cisco is urging customers to patch a maximum-severity zero-day vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products, warning that attackers are actively exploiting the flaw in the wild. The vulnerability, tracked as CVE-2026-76460, allows remote attackers to bypass authentication by sending a crafted request to an affected API endpoint, regardless of how the system is configured. A successful exploit gives the attacker unauthorized access to the affected device through the web-based management interface.

Cisco ISE is a centralized policy platform that IT administrators use to manage endpoint, user, and device access to network resources, often as part of Zero Trust security models. The company's Product Security Incident Response Team confirms active exploitation and says no workarounds exist, making it critical for administrators to apply the fixed software releases. Patches are available for all affected branches, including 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4.

Cisco has shared indicators of compromise and advises security teams to inspect access.log files on every node for suspicious usernames. If malicious activity is found, the company strongly recommends re-imaging affected nodes and restoring them from backups. Admins should also review firewall and network logs for suspicious downloads or uploads involving external or malicious IP addresses, since attackers may erase evidence after gaining root-level command execution. The update comes alongside fixes for a second maximum-severity authentication bypass flaw and five other critical issues in the same products.

Read More at the original source →