Who is affected
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) are affected. The vulnerability allows unauthenticated, remote attackers to bypass the web-based management interface and gain unauthorised access. The record does not specify which versions are vulnerable or whether only internet-facing deployments are at risk, so you must establish both.
How to check whether this touches you
- Search your asset inventory for any instance of Cisco ISE or ISE-PIC in your infrastructure.
- Determine whether the management interface (typically port 443) is reachable from untrusted networks, including the internet.
- Check the running version against Cisco's advisory; version fingerprints are visible in the ISE admin console and via SSH, but note that some organisations backport security fixes to older versions.
- If you operate ISE-PIC, verify which ISE instance it is connected to and whether that instance is exposed.
- Identify any change-management or configuration-management records showing when ISE was last patched.
What to do
- Immediately locate the authoritative Cisco security advisory for CVE-2026-76460 and read the full scope, affected versions, and patching timeline; CISA's record does not list specific patch versions.
- If the management interface is internet-reachable and you cannot patch within the federal due date (2026-09-19), restrict network access to that interface using firewall rules or access control lists; allow only administrative IP ranges.
- Apply any interim mitigations published by Cisco before patching is available.
- Once patching guidance is released, schedule and apply patches in order of exposure risk (internet-facing instances first).
- Enable detailed logging on the ISE management interface and review access logs for unusual authentication attempts or successful logins from unexpected sources.
- Escalate to your security operations centre if you find evidence of exploitation or unusual administrative activity dating back at least 90 days.
If you find you were exposed
Exploitation of unauthenticated remote access typically occurs before public disclosure, so you should search ISE logs and any upstream network sensors for suspicious access to the management interface at least three months before the CISA advisory date. Review who accessed the ISE admin console, from which IP addresses, and what configuration or credential changes were made. Log retention is often the limiting factor; if your ISE logging is set to a short retention window, that window may have already expired and you may have no record to examine.