PT-2026-94017 · Cisco · Ise+1

CVE-2026-76460

·

Published

2026-09-14

·

Updated

2026-10-02

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco ISE versions 3.1 patches 8 through 11 Cisco ISE versions 3.2 patches 7 through 10 Cisco ISE versions 3.3 patches 1 through 11 Cisco ISE versions 3.4 base 3.4.0 through patch 6 Cisco ISE versions 3.5 base 3.5.0 through patch 3 Cisco ISE-PIC versions 3.4.0 through 3.5.0
Description An authentication bypass exists in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) due to insufficient authentication control on an API endpoint. A remote, unauthenticated attacker can send a crafted request to the affected API endpoint to bypass the web-based management interface and gain unauthorized administrative access. Successful exploitation may lead to root-level command execution, which could allow an attacker to conceal evidence of the compromise. Cisco PSIRT and CISA have confirmed that this issue is being actively exploited in the wild.
Recommendations Update Cisco ISE version 3.1 to Patch 12. Update Cisco ISE version 3.2 to Patch 11. Update Cisco ISE version 3.3 to Patch 12. Update Cisco ISE version 3.4 to Patch 7. Update Cisco ISE version 3.5 to Patch 4. Update Cisco ISE-PIC to the appropriate fixed release. As a temporary mitigation, implement infrastructure ACLs (iACLs) to restrict incoming traffic to only essential management and control-plane flows. If a compromise is suspected, re-image the affected nodes and restore configuration from a known secure backup.

Exploit

Fix

RCE

DoS

LPE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14615
BDU:2026-14799
CVE-2026-76460

Affected Products

Ise
Ise-Pic