Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
CVSS 10.0 auth bypass in Cisco ISE and ISE-PIC. Unauthenticated attackers can bypass web management and gain root execution. Actively exploited; CISA KEV.
- Vendor
- Cisco
- Product
- Identity Services Engine
- CVSS
- 10.0
- EPSS (exploit probability)
- 14.0%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
CVE-2026-76460 is a CVSS 10.0 (critical) authentication bypass affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) across all supported release branches (3.1 through 3.5).
The flaw is an incorrect use of privileged APIs on an API endpoint in the web-based management interface. An unauthenticated, remote attacker can send crafted requests to that endpoint to bypass authentication, gain access to the management interface, and achieve root-level command execution on the affected device. Cisco’s advisory notes that successful exploitation can allow an attacker to hide or delete forensic indicators of compromise on the device.
Affected versions: ISE and ISE-PIC 3.1, 3.2, 3.3, 3.4, and 3.5 before the patched releases below.
Patches:
- ISE/ISE-PIC 3.5: Patch 4
- ISE/ISE-PIC 3.4: Patch 7
- ISE/ISE-PIC 3.3: Patch 12
- ISE/ISE-PIC 3.2: Patch 11
- ISE/ISE-PIC 3.1: Patch 12
No workarounds are available. Cisco recommends re-imaging any node suspected of compromise rather than attempting forensic cleanup.
CISA added this CVE to the Known Exploited Vulnerabilities catalog on September 16, 2026, with a remediation deadline of September 19, 2026 for federal civilian agencies under BOD 26-04.
Sources: NVD | CISA KEV catalog
