Cisco ISE Flaw Gives Attackers Root Access Without Login

Cisco has disclosed an actively exploited maximum-severity flaw in Identity Services Engine and ISE-PIC. The bug can give remote attackers root-level command execution without credentials.
Cisco ISE Flaw Gives Attackers Root Access Without Login
Share

Cisco disclosed an actively exploited, maximum-severity authentication-bypass vulnerability in Identity Services Engine on September 17. Tracked as CVE-2026-76460, the flaw carries a CVSS score of 10.0 and can give a remote attacker command execution with root privileges. It also affects Cisco ISE Passive Identity Connector.

The company said inadequate authentication checks on an API endpoint create the opening, as first reported by The Register. Attackers need no credentials or user interaction, and reported exploitation involves the products’ web-based management interface.

Root access raises the stakes for network controls

Identity Services Engine manages network access control, making it a central system for organizations that use it to govern which users and devices can connect. An intruder with root-level control of an affected appliance could alter its operation and hide evidence of a compromise.

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog. That listing signals that federal civilian agencies must address the issue under CISA’s binding remediation process, while also giving private-sector defenders a clear warning that exploitation has moved beyond a theoretical risk.

Patches are available, but no workaround exists

Cisco has released fixes for supported releases and advises administrators to examine ISE access logs alongside external network and firewall logs for indicators of compromise. When exploitation is confirmed, the vendor recommends reimaging affected nodes and restoring their configurations from backups.

  • ISE and ISE-PIC 3.1 Patch 12
  • ISE and ISE-PIC 3.2 Patch 11
  • ISE and ISE-PIC 3.3 Patch 12
  • ISE and ISE-PIC 3.4 Patch 7
  • ISE and ISE-PIC 3.5 Patch 4

No workaround is available. Infrastructure access control lists can restrict traffic to vulnerable management and control-plane interfaces, which may reduce exposure while teams deploy updates. Cisco ISE 3.0 is outside its software-maintenance period, so organizations on that release must migrate to a supported version.

Cisco has not publicly identified the attackers, their targets, the campaign behind the activity, or the number of organizations affected. Available information also does not establish when exploitation began, how widely it has occurred, the exploit’s technical details, or whether successful attacks have been confirmed in specific deployments.

This article was produced with AI assistance from multi-source reporting and is published under our editorial standards.

Anthropic Merges Claude Chat and Cowork, Adds Claude Docs

Anthropic Merges Claude Chat and Cowork, Adds Claude Docs

Prev