{"id":199,"date":"2026-09-25T21:28:33","date_gmt":"2026-09-25T21:28:33","guid":{"rendered":"https:\/\/managedt.com\/blog\/cisco-ise-zero-day-authentication-bypass\/"},"modified":"2026-10-09T03:03:06","modified_gmt":"2026-10-09T03:03:06","slug":"cisco-ise-zero-day-authentication-bypass","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/cisco-ise-zero-day-authentication-bypass\/","title":{"rendered":"Cisco ISE Zero-Day Authentication Bypass Vulnerability Under Active Exploitation"},"content":{"rendered":"<p>Cisco disclosed a maximum-severity zero-day vulnerability in its Identity Services Engine on September 16, 2026, allowing attackers to bypass API authentication and gain root-level access without credentials or user interaction. The flaw, tracked as CVE-2026-76460, is already under active exploitation and has been added to CISA&#8217;s Known Exploited Vulnerabilities catalog on the same day. Organizations running ISE or ISE-PIC versions 3.1 through 3.5 should apply patches immediately.<\/p>\n<h2>What Is CVE-2026-76460?<\/h2>\n<p>CVE-2026-76460 is an authentication bypass vulnerability in an API endpoint within Cisco Identity Services Engine, the company&#8217;s network access control and zero-trust solution. The flaw stems from insufficient authentication control on an affected API endpoint, allowing an attacker to send a crafted request that bypasses the web-based management interface entirely.<\/p>\n<p>Successful exploitation gives the attacker root privileges and command execution on vulnerable instances. No authentication or user interaction is required, making the vulnerability especially dangerous in environments where the management interface is exposed to untrusted networks.<\/p>\n<h2>Why ISE Compromise Puts the Entire Network at Risk<\/h2>\n<p>The danger of CVE-2026-76460 extends well beyond the affected device. ISE serves as the access control backbone for many organizations, determining which users and devices can connect to a network and what resources they can reach after connecting. Other Cisco APIs rely on ISE for authentication and access decisions, so an attacker who compromises ISE can effectively replace the security gatekeeper with a trusted imposter.<\/p>\n<p>Once ISE is compromised, the applications and network services that rely on its access decisions may start authorizing unauthorized users or devices.<\/p>\n<h2>A Pattern of API Authentication Failures<\/h2>\n<p>The ISE zero-day is not an isolated incident for Cisco. Two similar vulnerabilities were disclosed earlier in 2026, both involving insufficient authentication on API endpoints:<\/p>\n<ul>\n<li><strong>CVE-2026-20223<\/strong>, disclosed in May, is an insufficient authentication flaw in the internal REST APIs of Cisco Secure Workload. It received a maximum CVSS score of 10 out of 10.<\/li>\n<li><strong>CVE-2026-20129<\/strong>, disclosed in February, is a critical API authentication bypass in Cisco Catalyst SD-WAN Manager with a 9.8 CVSS score. That flaw could allow an attacker to execute commands with the privileges of the netadmin role.<\/li>\n<\/ul>\n<p>As organizations expose more APIs to support web application interfaces, authentication and access controls are sometimes omitted or simplified, creating direct paths to sensitive internal systems.<\/p>\n<h2>Who Is Exploiting CVE-2026-76460?<\/h2>\n<p>As of the disclosure, the identity of the threat actors exploiting CVE-2026-76460 and the scale of the activity remain unclear. Cisco released a brief statement that mirrored the advisory language but did not address questions about attribution or exploitation volume.<\/p>\n<h2>Affected Products and Patch Status<\/h2>\n<p>CVE-2026-76460 affects both ISE and ISE Passive Identity Connector (ISE-PIC) regardless of device configuration. Cisco has released patches for versions 3.1 through 3.5 of both products. Version 3.0 is no longer supported; customers running that version must upgrade to a fixed release.<\/p>\n<h2>Mitigation Steps and Temporary Workarounds<\/h2>\n<p>Cisco recommends deploying infrastructure access control lists (iACLs) to restrict management and control plane traffic to the affected devices as a temporary mitigation. iACLs can block remote exploitation by limiting which sources can reach the vulnerable API endpoints.<\/p>\n<p>However, Cisco cautioned that any workaround is only a temporary stopgap. Organizations should move to a fixed version of ISE or ISE-PIC as soon as possible. Successful exploitation grants root privileges, allowing attackers to delete or conceal evidence of compromise and remove indicators of compromise (IoCs) from the device itself.<\/p>\n<p>Because on-device logs may be tampered with, Cisco strongly recommends cross-checking network logs and external firewall logs for suspicious activity. Signs to look for include unexpected outbound uploads from the affected device to external IP addresses, and inbound downloads from known malicious IP addresses.<\/p>\n<h2>Broader Lessons for API Security<\/h2>\n<p>The recurring pattern of API authentication bypasses across Cisco products highlights a common gap in enterprise security programs. API endpoints that were never meant to be externally reachable are sometimes exposed during cloud migrations, management interface overhauls, or third-party integrations, and the authentication layer that protected them internally is stripped out in the process.<\/p>\n<p>Security teams should audit every API endpoint exposed by critical infrastructure components and confirm that each one enforces authentication and access control independently of the underlying system&#8217;s own trust mechanisms. Relying on a single component to gate access for an entire network creates a single point of failure that, once compromised, undermines every downstream protection.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is CVE-2026-76460?<\/h3>\n<p>CVE-2026-76460 is a maximum-severity authentication bypass vulnerability in Cisco Identity Services Engine (ISE) that allows an attacker to gain root-level access by sending a crafted request to an affected API endpoint. No authentication or user interaction is required.<\/p>\n<h3>Which Cisco products are affected?<\/h3>\n<p>CVE-2026-76460 affects Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) regardless of configuration. Patches are available for versions 3.1 through 3.5; version 3.0 is no longer supported and must be upgraded.<\/p>\n<h3>What should organizations do to protect against CVE-2026-76460?<\/h3>\n<p>Apply the Cisco patches for ISE and ISE-PIC as soon as possible. As a temporary measure, deploy infrastructure access control lists (iACLs) to limit management traffic to affected devices. Also review external network and firewall logs for unexpected uploads or downloads involving the affected systems, since on-device logs may be altered by an attacker.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is CVE-2026-76460?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CVE-2026-76460 is a maximum-severity authentication bypass vulnerability in Cisco Identity Services Engine (ISE) that allows an attacker to gain root-level access by sending a crafted request to an affected API endpoint. No authentication or user interaction is required.\"}},{\"@type\":\"Question\",\"name\":\"Which Cisco products are affected?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CVE-2026-76460 affects Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) regardless of configuration. Patches are available for versions 3.1 through 3.5; version 3.0 is no longer supported and must be upgraded.\"}},{\"@type\":\"Question\",\"name\":\"What should organizations do to protect against CVE-2026-76460?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Apply the Cisco patches for ISE and ISE-PIC as soon as possible. As a temporary measure, deploy infrastructure access control lists (iACLs) to limit management traffic to affected devices. Also review external network and firewall logs for unexpected uploads or downloads involving the affected systems, since on-device logs may be altered by an attacker.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/cisco-zero-day-api-endpoint-authentication-issues\" target=\"_blank\" rel=\"nofollow noopener\">darkreading.com<\/a>.<\/p>\n<p><!-- seo-pro:slop-fixed --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cisco disclosed a maximum-severity zero-day flaw in Identity Services Engine that allows attackers to bypass API authentication and gain root access.<\/p>\n","protected":false},"author":3,"featured_media":198,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-199","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=199"}],"version-history":[{"count":2,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/199\/revisions"}],"predecessor-version":[{"id":517,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/199\/revisions\/517"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/198"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}