Full Report
ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch
Analysis Summary
# Vulnerability: Cisco ISE Authentication Bypass and Remote Code Execution
## CVE Details
- **CVE ID:** CVE-2026-76460
- **CVSS Score:** 10.0 (Critical)
- **CWE:** Improper Authentication / Authentication Bypass
## Affected Systems
- **Products:** Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC)
- **Versions:**
- ISE/ISE-PIC 3.1 (Prior to Patch 12)
- ISE/ISE-PIC 3.2 (Prior to Patch 11)
- ISE/ISE-PIC 3.3 (Prior to Patch 12)
- ISE/ISE-PIC 3.4 (Prior to Patch 7)
- ISE/ISE-PIC 3.5 (Prior to Patch 4)
- ISE 3.0 (End of Software Maintenance; no fix available)
- **Configurations:** All configurations are affected.
## Vulnerability Description
The vulnerability exists due to insufficient authentication controls on a specific API endpoint within the Cisco ISE web-based management interface. An unauthenticated remote attacker can exploit this by sending a specially crafted request to the vulnerable API. Successful exploitation allows the attacker to bypass authentication and gain full command execution with **root privileges** on the underlying operating system.
## Exploitation
- **Status:** Exploited in the wild (Confirmed by Cisco PSIRT and CISA KEV catalog).
- **Complexity:** Low (No user interaction or credentials required).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** Total (Full access to data and credentials).
- **Integrity:** Total (Ability to modify configurations and delete/conceal logs).
- **Availability:** Total (Root access allows for complete system shutdown or disruption).
## Remediation
### Patches
Cisco recommends immediate updates to the following versions:
- **ISE / ISE-PIC 3.1:** Upgrade to Patch 12
- **ISE / ISE-PIC 3.2:** Upgrade to Patch 11
- **ISE / ISE-PIC 3.3:** Upgrade to Patch 12
- **ISE / ISE-PIC 3.4:** Upgrade to Patch 7
- **ISE / ISE-PIC 3.5:** Upgrade to Patch 4
*Note: Users on ISE 3.0 must migrate to a supported release.*
### Workarounds
- **No direct workaround exists.**
- **Temporary Mitigation:** Implement infrastructure access control lists (iACLs) to restrict management and control-plane traffic to the ISE interface to trusted IP addresses only.
## Detection
- **Log Analysis:** Review ISE access logs for suspicious or unauthorized usernames across all nodes in a distributed deployment.
- **External Monitoring:** Inspect network and firewall logs (stored off-device) for unexpected data uploads or downloads from ISE nodes.
- **Incident Response:** If indicators of compromise (IoCs) are found, Cisco recommends reimaging the affected nodes and restoring from a known-good backup, as root-level access allows attackers to hide their presence.
## References
- **Cisco Security Advisory:** hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
- **CISA KEV Catalog:** hxxps[://]www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog