News

Cisco ISE API bypass can reach root

Louis Stowasser
Louis Stowasser
Thursday 17 September 2026
Cisco ISE API bypass can reach root
Cisco ISE API bypass can reach root

Cisco Identity Services Engine (ISE) is the policy engine behind many organisations’ network admission decisions: it identifies users and devices, authenticates connections, evaluates endpoint posture and tells wired, wireless and VPN infrastructure what access to grant. Its Passive Identity Connector (ISE-PIC) sibling shares identity information with other network and security tools. That places these products in enterprises, campuses, regulated environments, and organisations managing large populations of guests, contractors, BYOD devices, IoT or operational technology.

CVE-2026-76460 is an actively exploited flaw in that management layer. Cisco published its advisory on September 16, 2026, and says it is aware of active exploitation; CISA added it to the Known Exploited Vulnerabilities catalogue the same day, with a September 19 remediation due date. No public reporting identifies a threat actor, victims, a campaign, or ransomware use.

A crafted request skips authentication

Cisco describes the issue as insufficient authentication control on an API endpoint, while CISA calls it incorrect use of privileged APIs. They describe the same vulnerability, not separate defects. An unauthenticated remote attacker can send a crafted request to the affected endpoint and bypass the web-based management interface’s normal login checks.

That distinction matters: the attacker does not need an ISE account, prior access to the network, or user interaction. They need network reachability to the vulnerable management/API service. Cisco says successful exploitation can provide unauthorized device access and may lead to command execution with root privileges. At that point, an intruder could alter the appliance and hide or remove evidence and indicators.

Cisco has not published the endpoint, crafted-request format, or source-level patch details, so defenders should not assume that blocking a guessed URL is meaningful protection. The issue was found during a Cisco Technical Assistance Center support case and is tracked as Cisco Bug ID CSCww39530.

Fixed releases exist; there is no workaround

Cisco’s advisory names these first fixed releases:

  • ISE 3.1 Patch 12

  • ISE 3.2 Patch 11

  • ISE 3.3 Patch 12

  • ISE 3.4 Patch 7

  • ISE 3.5 Patch 4

Earlier patch levels in those branches are affected, for both ISE and ISE-PIC regardless of configuration. ISE 3.0 is out of software maintenance; Cisco does not provide a fixed 3.0 patch and advises migration to a supported fixed release. ISE-PIC’s last supported release is 3.4, so the 3.5 Patch 4 entry applies to ISE rather than ISE-PIC.

There is no workaround. While patching is being scheduled, restrict management and control-plane traffic with infrastructure ACLs to the specific administrative sources that require it. That is mitigation, not removal of the defect. Review each node’s API gateway access logs for suspicious usernames, then correlate firewall and network telemetry for unexpected access and uploads or downloads. If compromise is suspected, Cisco recommends re-imaging affected nodes and restoring configuration from backup.

Exploitation changes the response

No public proof of concept or exploit code had surfaced as of September 17, 2026. Active exploitation still means attackers possess a workable method, and the absence of published details is not a reason to delay.

For teams running ISE, this is a patch-and-investigate event, especially where management access is broadly reachable. Inventory both ISE and ISE-PIC, constrain exposure now, and use SecAlerts to monitor the software actually in your stack and alert on vulnerabilities affecting the products you run.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203