OFFSEC · Offensive Security

The exploited Cisco ISE flaw is a trust problem, not a patching problem

CVE-2026-76460 carries a CVSS of 10.0 and a scope-change metric. Root on an Identity Services Engine node means the credentials, certificates and access policy it holds must be treated as lost, and Cisco's only published indicator lives on the compromised device.

A perfect score on the device that decides who joins the network

Cisco published advisory cisco-sa-ISE-ABP-VNSW7Tn5 on 16 September 2026, covering CVE-2026-76460 in Identity Services Engine and the ISE Passive Identity Connector [1]. The base score is 10.0, the vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, and the weakness class is CWE-648, incorrect use of privileged APIs [1]. Cisco states that “The Cisco PSIRT is aware of active exploitation of this vulnerability” and that “There are no workarounds that address this vulnerability” [1].

The score is not the finding. The scope-change metric is. S:C is Cisco recording that successful exploitation crosses the security boundary of the appliance itself, and on this appliance that boundary is network admission policy for everything behind it.

There are no workarounds that address this vulnerability.

Cisco Security Advisory cisco-sa-ISE-ABP-VNSW7Tn5, 16 September 2026

What root on ISE actually reaches

ISE is a policy decision point. It authenticates users and devices, profiles endpoints, and issues the authorisation results that switches, wireless controllers and VPN concentrators enforce. The Cloud Security Alliance's research note describes it as the central policy decision point for network access control and zero-trust enforcement, and states that root access permits an attacker to modify access policy, exfiltrate stored credentials and certificates, and manipulate or delete forensic logs [11].

Named assessments converge on the same point and should be read as those researchers' views rather than as established fact. Landon Rice of VulnCheck told CyberScoop that root on the appliance lets an attacker modify policy, extract stored credentials, delete logs and move laterally into every segment ISE controls [5]. Johannes Ullrich of the SANS Internet Storm Center told Dark Reading that “Missing authentication for API endpoints is an industry-wide problem”, and that ISE's role means root there allows an attacker to impersonate legitimate systems enterprise-wide [10]. Emma Stevens of Bitsight, in the same piece, said root-level access to that infrastructure “can create visibility, integrity, and availability risks across a much wider environment” [10].

How it was found, and how fast the clock ran

Cisco found the flaw while resolving a technical support case, according to CyberScoop and The Register [5][6]. That is a discovery route that implies at least one customer was already in difficulty. Cisco has not said how many were affected [5].

CISA added the CVE to the Known Exploited Vulnerabilities catalogue on 16 September 2026 with a federal remediation deadline of 19 September, a three-day window against the catalogue's usual three weeks [7][9][12]. cisa.gov did not respond to retrieval, so those dates are carried here from publishers quoting the catalogue directly rather than from the catalogue itself.

The advisory landed inside an unusually wide release. Cisco's advance notification, issued seven days earlier, covered Identity Services Engine, Secure Firewall including ASA, FTD and FMC, Nexus Dashboard, BroadWorks and the ThousandEyes virtual appliance, with critical ratings spanning 9.0 to 10.0 [3]. A separate ISE hardening advisory published the same day bundles six further vulnerability classes, including insufficient credential protection, also with no workarounds [2]. The Register records two further CVSS 10.0 ISE CVEs published on the same date [6]. Two days earlier, CVE-2026-76461 in Cisco Secure Email Gateway, CVSS 9.8, was already being exploited [13].

Affected versions are reported inconsistently. Cisco's advisory and Singapore's Cyber Security Agency list ISE and ISE-PIC 3.1 through 3.5 [1][4]. Several readers of the advisory place 3.0 in scope as well, with migration rather than a patch as the only route because it is out of software maintenance [6][8][11]. Fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4 [1].

The indicator sits on the attacker's side of the line

Cisco's detection guidance is to review the access log for suspicious usernames, using show logging application ise-kong/access.log, and to collect support bundles with debug logging enabled [1]. Singapore's CSA repeats that guidance on 21 September and adds that logs from each node in a distributed deployment must be examined [4].

The difficulty is structural. Successful exploitation yields root. SecurityWeek notes that this potentially allows attackers to hide or delete evidence of compromise [9]; the Cloud Security Alliance note states directly that an attacker with root may have altered or deleted those logs [11]. The vendor's primary detection artefact is under the attacker's control. That is why Cisco, CSA Singapore and Dark Reading all direct defenders to network and firewall telemetry held outside the appliance [1][4][10]. SOCRadar adds that Cisco has not publicly identified the vulnerable endpoint, which is why the published indicator set is as thin as it is, and that no threat actor has been publicly named [17].

One measurement anomaly is worth recording. Tenable shows an EPSS score of 0.00915, under one per cent, for a vulnerability with vendor-confirmed exploitation and a KEV listing [12]. Any triage process weighted primarily on EPSS would have deprioritised this.

Patching is not remediation

Cisco and CSA Singapore both say that where malicious activity is suspected, the correct action is to re-image affected nodes and restore from configuration backup [1][4]. The Cloud Security Alliance goes further and advises treating any internet-reachable, unpatched ISE as potentially compromised [11].

The reason is what the appliance holds. Cisco's own administration guide confirms that ISE runs an internal certificate authority issuing endpoint and VPN user certificates, and documents procedures for CA chain regeneration and for backup and restoration of CA certificates and keys [15]. Exportable CA material on a device an unauthenticated attacker can reach as root is the whole argument. The same guide notes that a trust-chain change must propagate to every ISE node, endpoint control system and supplicant, which is the cost of distrust, and it documents no compromise-driven CA regeneration workflow [15].

A practical rotation set has been published, and it is the right scope: local administrator passwords, Active Directory join credentials, RADIUS and TACACS+ shared secrets, and ERS API credentials [16]. Most vendor commentary stopped at patching. It should not.

The pattern behind the CVE

This is the third actively exploited ISE flaw since June 2025 [5]. CERT-EU recorded CVE-2025-20281, CVE-2025-20282 and CVE-2025-20337 in July 2025, all CVSS 10.0, two of them unauthenticated API defects reaching root [14]. Critically, the first round of patches did not protect against CVE-2025-20337; customers had to reach 3.3 Patch 7 or 3.4 Patch 2 [14]. Dark Reading places the current flaw in a wider run of Cisco API authentication defects, citing CVE-2026-20223 in Secure Workload and CVE-2026-20129 in Catalyst SD-WAN Manager [10].

The operational lesson from 2025 is that version numbers are not patch numbers. An estate that reports itself on 3.4 is reporting nothing useful.

What to do

  • Inventory every ISE and ISE-PIC node, including secondary nodes and disaster-recovery appliances, and verify patch level rather than release [1].
  • Confirm no ISE administrative or API interface is reachable from the internet, and apply infrastructure access control lists to management and control plane traffic as an interim measure only [4].
  • Hunt in off-box telemetry first: firewall and NetFlow records for unexpected outbound transfers from ISE nodes, and for administrative logins from outside designated management ranges [1][10].
  • If compromise is suspected, plan for re-image plus rotation of local admin credentials, AD join accounts, RADIUS and TACACS+ shared secrets and ERS API credentials, and treat the internal CA as needing regeneration [4][15][16].
  • Patch the wider September batch, not only the exploited CVE. The hardening advisory covers insufficient credential protection on the same appliance [2][3].

Domain close

Security appliances are rated as products and deployed as trust anchors. The CVSS vector for this flaw says so explicitly: scope changed. An organisation that patches ISE and closes the ticket has restored the appliance and left the trust material it issued in whatever state the attacker chose. The question to ask of any control-plane device is not whether it is patched, but what would have to be reissued if it were not. On ISE the answer includes the certificates by which endpoints prove they belong on the network.

Sources

Every R3KONX article cites its primary material. 17 sources, in order of first citation. Links open the original publication.

  1. Cisco Identity Services Engine Authentication Bypass Vulnerability (cisco-sa-ISE-ABP-VNSW7Tn5) Cisco Product Security Incident Response Team · 2026-09-16
  2. Cisco Identity Services Engine Hardening Release: September 2026 (cisco-sa-hardening-ise-XU5EwX5T) Cisco Product Security Incident Response Team · 2026-09-16
  3. Cisco Advance Notification for Publication of September 16, 2026 Security Advisories Cisco · 2026-09-09
  4. Active Exploitation of Vulnerability in Cisco Identity Services Engine (AL-2026-126) Cyber Security Agency of Singapore · 2026-09-21
  5. Cisco alerts customers to second actively exploited zero-day in as many days CyberScoop · 2026-09-17
  6. Cisco drops another exploited zero-day, this time a perfect 10 The Register · 2026-09-17
  7. Cisco warns of max severity ISE zero-day exploited in attacks BleepingComputer · 2026-09-17
  8. Unauthenticated attackers are bypassing Cisco ISE's management interface (CVE-2026-76460) Help Net Security · 2026-09-17
  9. Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day SecurityWeek · 2026-09-17
  10. Cisco Zero-Day Highlights API Endpoint Authentication Issues Dark Reading · 2026-09-18
  11. CSA Research Note: Cisco ISE Auth Bypass (CVE-2026-76460) Cloud Security Alliance Labs · 2026-09-17
  12. CVE-2026-76460 Tenable · 2026-09-16
  13. ETR: CVE-2026-76461 Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild Rapid7 · 2026-09-15
  14. Critical Vulnerabilities in Cisco Identity Services Engine (Advisory 2025-025) CERT-EU · 2025-07-18
  15. Cisco Identity Services Engine Administrator Guide, Release 3.4 - Basic Setup Cisco · 2025-01-01
  16. CVE-2026-76460: Cisco ISE privileged API exploitation in the wild - detection and remediation guide Security Arsenal · 2026-09-17
  17. CVE-2026-76460: Cisco ISE Flaw Actively Exploited SOCRadar · 2026-09-17

This article was researched and written by the R3KONX analysis desk from the cited primary material. Methodological caveat: cisa.gov returned HTTP 403 to retrieval, so the KEV listing date of 16 September 2026 and the 19 September federal remediation deadline are carried from publishers that were readable and that quote CISA directly, rather than from the catalogue itself. No figure is given for internet-exposed ISE deployments because no retrievable source publishes one. No exploit mechanics are reproduced. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.