Cisco Issues Emergency Patches for CVE-2026-76460 ISE Zero-Day After Active Exploitation Confirmed
Cisco patched an actively exploited CVSS 10.0 auth bypass in ISE after CISA KEV listing. Logs and external network checks are required to detect root-level intrusions. The event underscores recurring API exposure patterns in enterprise identity platforms.
The vulnerability stems from insufficient authentication controls on an exposed API endpoint in Cisco ISE. Attackers could send crafted requests to bypass the web management interface and obtain root privileges on affected appliances regardless of configuration. No workarounds exist beyond network-level iACL restrictions. Cisco PSIRT documented active exploitation and recommended immediate upgrades to 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11, or 3.1 Patch 12. Evidence of compromise appears in access.log files showing anomalous usernames on every node in distributed deployments. Successful exploitation permits root-level actions that can delete or conceal indicators, requiring cross-reference of external firewall and network logs for unexpected file transfers. CISA added the flaw to its KEV catalog on the same day with a three-day remediation mandate for federal agencies under BOD 26-04. This incident fits a recurring pattern in Cisco enterprise products where management-plane APIs become initial access vectors for both criminal and state-linked actors. Similar zero-days in Secure Email Gateway and other appliances show consistent targeting of identity and access control infrastructure. Independent technical confirmation of exploitation remains limited to vendor telemetry and CISA directives; no public attribution data distinguishes actor types. Organizations must now prioritize node re-imaging from known-good backups after log review. Future risk concentrates on unpatched ISE instances in large-scale deployments where API exposure cannot be fully segmented. Procurement records indicate continued heavy reliance on ISE for NAC functions, extending the window of exposure.
CISA: At least 40 federal agencies will miss the three-day BOD 26-04 deadline for CVE-2026-76460 remediation.
Sources (2)
- [1]SecurityWeek(https://www.securityweek.com/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day/)
- [2]CISA Known Exploited Vulnerabilities Catalog(https://www.cisa.gov/known-exploited-vulnerabilities-catalog)