A maximum-severity flaw in Cisco Identity Services Engine is under active attack, prompting the company to release security updates and the Cybersecurity and Infrastructure Security Agency to issue an emergency directive to federal agencies.
Cisco ISE serves as a centralized policy management platform enabling IT administrators to control endpoint, user, and device access to network resources, frequently deployed to support Zero Trust security architectures.
Vulnerability details
The flaw, designated CVE-2026-76460, resides in an API endpoint of both Cisco Identity Services Engine and Cisco ISE Passive Identity Connector (ISE-PIC). The vulnerability permits remote attackers to circumvent authentication controls independent of how the systems are configured.
This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Cisco
Active exploitation and remediation
Cisco's Product Security Incident Response Team confirmed on Wednesday that CVE-2026-76460 is being actively exploited. The company stated, "Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability."
No workarounds are available for this issue, making patching the sole protective measure. Security teams should examine access.log files across all nodes for unusual usernames and consider re-imaging systems and restoring from backups if compromise is suspected.
Organizations should also review firewall and network logs for indicators of suspicious activity, including anomalous data transfers to or from external and malicious IP addresses. Attackers with root-level command execution may attempt to erase exploitation evidence.
Related patches and government action
Cisco released patches yesterday for a second maximum-severity authentication bypass (CVE-2026-76423) and five additional critical vulnerabilities (CVE-2026-76460, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284) affecting ISE and ISE-PIC. These additional flaws have not yet been reported as actively exploited.
CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities Catalog on Wednesday and mandated that federal agencies complete patching within three days.
Historical context
In July 2025, attackers exploited a separate Cisco ISE zero-day (CVE-2025-20337) carrying a maximum severity rating to execute remote code and deploy a custom "IdentityAuditAction" web shell masquerading as a legitimate ISE component.
Over the past five years, CISA has cataloged 99 Cisco product vulnerabilities as actively exploited, with seven of those appearing in ransomware campaigns.