Cisco Identity Services Engine (ISE) Authentication Bypass Vulnerability
Release Date: 16th September 2026 (Added 21 September 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-76460 is a critical authentication bypass vulnerability in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The flaw resides in an API endpoint that does not enforce sufficient authentication controls, allowing an unauthenticated, remote attacker to send a crafted request and bypass the web-based management interface entirely.
The vulnerability (CWE-648, Incorrect Use of Privileged APIs) requires no user interaction, no existing privileges, and no special device configuration to be exploited. Cisco has confirmed active exploitation of this flaw in the wild, warning that successful exploitation may ultimately provide attackers with command execution as root - a level of access that can allow a threat actor to alter or conceal evidence of compromise. CVSS v3.1 score: 10.0 (Critical).
What are the systems affected?
The following version(s) are affected:
- Cisco Identity Services Engine (ISE), releases 3.1 through 3.5
- Cisco ISE Passive Identity Connector (ISE-PIC), releases 3.1 through 3.5
Note: Cisco ISE 3.0 has reached End of Software Maintenance and must be migrated to a supported release.
Not affected / patched version:
- ISE / ISE-PIC 3.1 Patch 12 and later
- ISE / ISE-PIC 3.2 Patch 11 and later
- ISE / ISE-PIC 3.3 Patch 12 and later
- ISE / ISE-PIC 3.4 Patch 7 and later
- ISE / ISE-PIC 3.5 Patch 4 and later
What does this mean?
Successful exploitation may allow attackers to:
- Gain unauthorized administrative access to the affected device without valid credentials
- Obtain command execution with root privileges
- Alter, conceal, or delete forensic evidence of compromise, complicating incident investigation
Mitigation process?
CERTVU recommends the following:
-
Apply the vendor patch immediately
Upgrade to the first fixed release for your version: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4. No workaround exists - patching is the only remediation. -
Treat this as top priority
-
Apply compensating controls if immediate patching is not possible
-
Investigate for prior compromise
-
Migrate off Cisco ISE 3.0
ISE 3.0 has reached End of Software Maintenance and has no fixed release for this vulnerability. Organizations still running 3.0 should migrate to a supported, patched release as soon as possible.
Reference
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-76460
- Download advisory (English): Cisco Identity Services Engine (ISE) Authentication Bypass Vulnerability