Cybersecurity

Cisco Warns of Exploitation of a Critical-Severity Vulnerability in Identity Services Engine

Cisco has released security updates to address the CVE-2026-76460 zero-day vulnerability in Identity Services Engine and ISE-PIC after confirming that it is being actively exploited in attacks. No workaround is available, making upgrading to the patched versions and carrying out the associated digital forensics a priority for network administrators.

2026-09-17
3 min read
7 views
فريق تحرير certi.news
Cisco Warns of Exploitation of a Critical-Severity Vulnerability in Identity Services Engine

Cisco warned of active exploitation of a critical-severity zero-day vulnerability in the Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) platforms and released updates to address it. The vulnerability is tracked as CVE-2026-76460 and allows a remote attacker to bypass authentication and gain unauthorized access to the management interface by exploiting a weakness in an API.

Cisco ISE is used as a centralized platform for managing users, devices, endpoints, and access policies for network resources, including environments that implement Zero Trust security models. According to Cisco’s description, the issue results from a weakness in the authentication controls for an API endpoint; a specially crafted request can, if exploitation succeeds, bypass the web-based management interface and provide access to the affected device.

Patched Versions

Cisco’s Product Security Incident Response Team (PSIRT) confirmed that it is aware of active exploitation of the vulnerability and urged customers to upgrade immediately. The company provides no temporary workaround, so the security updates represent the only recommended path for addressing the ongoing risk.

  • Version 3.1: Fixed in Patch 12.
  • Version 3.2: Fixed in Patch 11.
  • Version 3.3: Fixed in Patch 12.
  • Version 3.4: Fixed in Patch 7.
  • Version 3.5: Fixed in Patch 4.

What Should Security Teams Do?

Cisco asked security teams to look for suspicious usernames in the access.log files on every node. If indicators of malicious activity appear, the company strongly recommended rebuilding the affected nodes and restoring them from backups.

Teams should also review firewall and network logs for downloads or uploads from external or malicious IP addresses. Cisco warns that attackers may delete traces of exploitation after gaining execution capability with root privileges, meaning that the absence of clear evidence in a single log is not sufficient to rule out a compromise.

Why Does This Matter?

The importance of the vulnerability lies in the combination of three factors: authentication bypass, targeting a platform that controls network access policies, and confirmed exploitation in real-world attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to address it within three days.

Another Cisco ISE zero-day vulnerability, tracked as CVE-2025-20337, was previously exploited during July 2025 in attacks to execute remote commands and deploy a custom web shell named “IdentityAuditAction,” disguised as a legitimate ISE component. The article states that over the past five years, CISA classified 99 vulnerabilities in Cisco products as actively exploited, including seven vulnerabilities used in ransomware attacks.

Cisco also announced a fix for another authentication-bypass vulnerability and five critical security issues in ISE and ISE-PIC, but the article does not say that they have been classified as exploited so far. This section requires editorial review, as the text cites CVE-2026-76423 when referring to the second vulnerability and then lists CVE-2026-76460 among the identifiers, which is the same identifier for the exploited vulnerability discussed in the article.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news