News

Hackers Are Already Walking Past Login on Cisco Identity Services Engine Across Networks

Cisco PSIRT advisory cisco-sa-ISE-ABP-VNSW7Tn5, first published 16 September 2026 at 16:00 GMT, rates CVE-2026-76460 (CWE-648) CVSS 10.0. Unauthenticated requests can bypass ISE web management. Cisco says exploitation is active. CISA added it to KEV.

Hackers Are Already Walking Past Login on Cisco Identity Services Engine Across Networks

Cisco PSIRT published advisory cisco-sa-ISE-ABP-VNSW7Tn5 on 16 September 2026 at 16:00 GMT. SecurityWeek (Ionut Arghire, 17 September 2026) reported the same authentication bypass and the emergency patches.

This is a Cisco PSIRT advisory with known exploitation. Cisco has not named a threat actor and has not published a public proof of concept.

The bug is CVE-2026-76460 (CWE-648), scored CVSS 10.0. Insufficient authentication on an ISE API lets an unauthenticated attacker send a crafted request and bypass the web management interface. It affects Cisco ISE and ISE-PIC regardless of configuration. Cisco tracked it as CSCww39530 and found it while resolving a TAC case.

There is no workaround that fixes the flaw. Infrastructure access control lists (iACLs) can limit management traffic and are a temporary mitigation only. Fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Release 3.0 is end of software maintenance and needs a move to a supported train.

Cisco says a successful exploit may yield root and that attackers can hide indicators of compromise. Hunt access.log and ise-kong logs on every node. If a node looks compromised, Cisco says re-image it. CISA added the CVE to its Known Exploited Vulnerabilities catalog on 16 September 2026.

Related exploit tape includes Iranian Chosen Brick spyware, the CenterPoint 7.49 million customer breach, and OpenAI rogue agents on Hugging Face.

Upgrade every ISE node to a fixed release now, keep iACL management in place until that is done, and re-image any node that looks suspicious.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free