Cisco Urges Immediate Patching for Actively Exploited Identity Services Engine Vulnerability
**Cisco** has issued an urgent security advisory, urging customers to patch a maximum-severity vulnerability in its **Identity Services Engine (ISE)** and **ISE Passive Identity Connector (ISE-PIC)**. Tracked as **CVE-2026-76460**, this flaw is being actively exploited in the wild, allowing remote attackers to bypass authentication and gain unauthorized access to affected devices. With no available workarounds, immediate application of security updates is critical.

**Cisco** has released critical security updates to address a maximum-severity vulnerability within its **Identity Services Engine (ISE)**, a centralized policy platform vital for managing network access and enforcing Zero Trust security models. This flaw is currently under active exploitation by attackers.
### Authentication Bypass Exploited in the Wild
The security vulnerability, identified as **CVE-2026-76460**, allows remote attackers to bypass authentication. This is achieved by exploiting a weakness in an API of **Cisco ISE** and **Cisco ISE Passive Identity Connector (ISE-PIC)**, irrespective of the configuration.
**Cisco** elaborated on the issue, stating, "This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint." A successful exploit grants unauthorized access to the affected device by bypassing the web-based management interface.
### Urgent Call to Action from Cisco PSIRT
The **Cisco Product Security Incident Response Team (PSIRT)** has confirmed active exploitation of **CVE-2026-76460**. Consequently, **Cisco** strongly recommends that customers upgrade to a fixed software release without delay. Given the absence of workarounds, applying these security updates is the only recommended course of action to safeguard networks from ongoing attacks.
Here are the first fixed releases for the affected **Cisco ISE** or **ISE-PIC** versions:
| Cisco ISE or ISE-PIC Release | First Fixed Release |
| :--------------------------- | :------------------ |
| 3.1 | 3.1 Patch 12 |
| 3.2 | 3.2 Patch 11 |
| 3.3 | 3.3 Patch 12 |
| 3.4 | 3.4 Patch 7 |
| 3.5 | 3.5 Patch 4 |
### Indicators of Compromise and Remediation
**Cisco** has provided indicators of compromise (IoCs), advising security teams to scrutinize `access.log` files on every node for suspicious usernames. In cases of suspected malicious activity, **Cisco** "strongly" recommends re-imaging the affected nodes and restoring them from backups. Administrators should also cross-reference firewall and network logs for any signs of suspicious activity, including downloads and uploads to or from external or malicious IP addresses. Attackers may attempt to remove evidence of exploitation after gaining root privileges.
### Broader Security Updates and CISA Mandate
In related news, **Cisco** recently patched another maximum-severity authentication bypass flaw, **CVE-2026-76423**, and five other critical security issues in **Cisco ISE** and **ISE-PIC**. These additional vulnerabilities, tracked as **CVE-2026-76460**, **CVE-2026-20176**, **CVE-2026-20211**, **CVE-2026-20307**, and **CVE-2026-20284**, have not yet been flagged as actively exploited.
The **Cybersecurity and Infrastructure Security Agency (CISA)** has added **CVE-2026-76460** to its **Known Exploited Vulnerabilities (KEV) Catalog**. **CISA** has mandated that federal agencies patch their systems against this vulnerability within three days.
This is not the first time **Cisco ISE** has been targeted. In July 2025, threat actors exploited another **Cisco ISE** zero-day, **CVE-2025-20337**, with a maximum severity score, in remote code execution attacks to deploy a custom "IdentityAuditAction" web shell.
Over the past five years, **CISA** has identified 99 security flaws in **Cisco** products as actively exploited, with seven of these being abused in ransomware attacks.