2026-09-17: Attackers take over Cisco's network gatekeeper with a single request
Cisco has released emergency patches for Identity Services Engine, the system many organizations use to decide who and what is allowed onto their network. CVE-2026-76460 scores a maximum 10 out of 10 (Critical) CVSS score, and Cisco confirms cybercriminals were already exploiting it before the fix existed.
Read Cisco’s advisory here (external link).
How the vulnerability works
Identity Services Engine (ISE) is the gatekeeper of the corporate network. When a laptop, phone or printer connects, ISE checks who owns it, whether it meets policy, and what it can reach. Administrators manage all of that through a web interface protected by a login.
The vulnerability sits in one of the application programming interfaces (APIs) behind that web interface. Cisco says this API doesn't check properly whether the caller is authorized, so a specially crafted request walks straight past the login – an authentication bypass.
Why this is dangerous
Cybercriminals need no password, no account, and no help from an employee. One crafted request is enough, and Cisco's advisory describes exploitation leading to command execution with root privileges, the highest level of access a system has.
Because ISE decides who gets onto the network, taking it over is worth far more than taking over an ordinary server. Whoever controls it can grant themselves access to systems that should be off limits and rewrite the rules that keep untrusted devices out. They can also collect the credentials ISE uses to reach directory services, then delete the log entries that would show any of it happened.
Cisco's security team says it's aware of active exploitation, but it hasn't published details of the campaigns or named those responsible.
Affected software
Both ISE and ISE Passive Identity Connector (ISE-PIC) are affected, across releases 3.1 through 3.5. Cisco stresses that devices are vulnerable regardless of how they're configured, so no setting protects an unpatched system. Release 3.0 has reached end of life (EOL) and won't be fixed, so those deployments need to move to a supported release.
Mitigation & next steps
Fixes are available in ISE and ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. There are no workarounds. Cisco's only interim advice is to restrict management traffic to the appliance with access control lists. That limits who can reach the vulnerable interface, but it doesn't remove the vulnerability.
CISA added CVE-2026-76460 to its KEV Catalog on 16 September 2026, the same day Cisco published its advisory.
View the Catalog here (external link).
Holm Security’s response
Holm Security has released a test to scan for this vulnerability:
- HID-2-1-5409873 - Cisco Identity Services Engine Authentication Bypass Vulnerability (CVE-2026-76460)
Scan for specific vulnerabilities
Read how you can include or exclude a specific vulnerability in a scan profile here.