Cisco ISE authentication bypass CVE-2026-76460: what defenders need to do now
Cisco confirmed active exploitation of CVE-2026-76460 in Identity Services Engine: an unauthenticated attacker gains root via an API endpoint. Affected are ISE and ISE-PIC versions 3.1–3.5; fixes are in patches 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7, and 3.5 P4.
- CVSS 10.0: authentication bypass on API endpoint gives root without login
- Affected all Cisco ISE and ISE-PIC configurations releases 3.1–3.5
- No workarounds; need patch and ACL for management interfaces
- Attackers can erase logs; indicator is dummyuser account entries
Read next
Security