Cisco Identity Services Engine (ISE) Authentication Bypass Vulnerability

Release Date: 16th September 2026 (Added 21 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-76460 is a critical authentication bypass vulnerability in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The flaw resides in an API endpoint that does not enforce sufficient authentication controls, allowing an unauthenticated, remote attacker to send a crafted request and bypass the web-based management interface entirely.

The vulnerability (CWE-648, Incorrect Use of Privileged APIs) requires no user interaction, no existing privileges, and no special device configuration to be exploited. Cisco has confirmed active exploitation of this flaw in the wild, warning that successful exploitation may ultimately provide attackers with command execution as root - a level of access that can allow a threat actor to alter or conceal evidence of compromise. CVSS v3.1 score: 10.0 (Critical).

Reference

  1. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-76460