ZeroDayAlert

CVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Cisco Identity Services Engine Added to KEV 2026-09-16 Federal due 2026-09-19 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) are affected. The vulnerability allows unauthenticated, remote attackers to bypass the web-based management interface and gain unauthorised access. The record does not specify which versions are vulnerable or whether only internet-facing deployments are at risk, so you must establish both.

How to check whether this touches you

  • Search your asset inventory for any instance of Cisco ISE or ISE-PIC in your infrastructure.
  • Determine whether the management interface (typically port 443) is reachable from untrusted networks, including the internet.
  • Check the running version against Cisco's advisory; version fingerprints are visible in the ISE admin console and via SSH, but note that some organisations backport security fixes to older versions.
  • If you operate ISE-PIC, verify which ISE instance it is connected to and whether that instance is exposed.
  • Identify any change-management or configuration-management records showing when ISE was last patched.

What to do

  1. Immediately locate the authoritative Cisco security advisory for CVE-2026-76460 and read the full scope, affected versions, and patching timeline; CISA's record does not list specific patch versions.
  2. If the management interface is internet-reachable and you cannot patch within the federal due date (2026-09-19), restrict network access to that interface using firewall rules or access control lists; allow only administrative IP ranges.
  3. Apply any interim mitigations published by Cisco before patching is available.
  4. Once patching guidance is released, schedule and apply patches in order of exposure risk (internet-facing instances first).
  5. Enable detailed logging on the ISE management interface and review access logs for unusual authentication attempts or successful logins from unexpected sources.
  6. Escalate to your security operations centre if you find evidence of exploitation or unusual administrative activity dating back at least 90 days.

If you find you were exposed

Exploitation of unauthenticated remote access typically occurs before public disclosure, so you should search ISE logs and any upstream network sensors for suspicious access to the management interface at least three months before the CISA advisory date. Review who accessed the ISE admin console, from which IP addresses, and what configuration or credential changes were made. Log retention is often the limiting factor; if your ISE logging is set to a short retention window, that window may have already expired and you may have no record to examine.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-76460 is being exploited. It cannot tell you whether Identity Services Engine is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →