Active Exploitation of Vulnerability in Cisco Identity Services Engine
21 September 2026
Attackers are exploiting a critical vulnerability in Cisco Identity Services Engine and Cisco Identity Services Engine Passive Identity Connector to bypass authentication and gain unauthorised access. Patch immediately.
Background
Cisco has released security updates to address a critical vulnerability (CVE-2026-76460) affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector. This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 10.0 out of 10.
Impact
Successful exploitation of the vulnerability, due to insufficient authentication control, could allow an attacker to gain unauthorised access to the affected device by sending a crafted request to an affected API endpoint, thereby bypassing the web-based management interface.
Known Exploitation
This vulnerability is reportedly being actively exploited.
Affected Products
The vulnerability affects the following products:
Cisco ISE versions 3.1, 3.2, 3.3, 3.4 and 3.5
Cisco ISE Passive Identity Connector versions 3.1, 3.2, 3.3, 3.4 and 3.5
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
If immediate patching is not possible, administrators should use infrastructure access control lists to allow only required management and control plane traffic destined for the affected device to prevent remote exploitation of this vulnerability.
To confirm any attempted exploitation of this vulnerability, users and administrators should review the access.log and look for suspicious usernames. If the device is part of a distributed deployment, the logs of each node should be reviewed.
The following is a non-exhaustive example of how a suspicious username could be detected in the logs:
admin#show logging application ise-kong/access.log | include dummyuser
To view additional access.log files, collect a support bundle with include debug logs selected, use shared key encryption, and then decrypt and find the access logs at:
./ise/logs/apigateway/access.log..gz.
The presence of any entry in the output may indicate malicious activity. If malicious activity is suspected, it is strongly recommended to re-image the affected nodes and restore from configuration backup, if needed.
References
https://nvd.nist.gov/vuln/detail/CVE-2026-76460 (opens in new tab)
