What happened
On September 16, 2026, Cisco published the CVE-2026-76460 advisory and confirmed active exploitation. CVE-2026-76460 is a CVSS 10.0 authentication bypass in an API of Cisco ISE and Cisco ISE-PIC that is exploitable remotely without authentication. A successful exploit can bypass the web management interface and may provide command execution with root privileges. Cisco says the vulnerability affects both products regardless of device configuration.
Fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4; Cisco advises 3.0 users to migrate to a supported fixed release. Cisco says there is no workaround; infrastructure access-control lists restricting management and control-plane traffic are a temporary mitigation. Those restrictions reduce remote exposure but do not replace upgrading or reviewing earlier activity.
Cisco’s published hunt command is: admin#show logging application ise-kong/access.log | include dummyuser. Cisco advises running the check on every node in a distributed deployment and reviewing network and firewall telemetry outside the appliance for unexpected transfers. The cited sources did not publish attacker IP addresses, domains, hashes, filenames or a named malware family.
On September 17, 2026, the Canadian Centre for Cyber Security urged immediate remediation and compromise review. CISA added CVE-2026-76460 to the Known Exploited Vulnerabilities Catalog on September 16, 2026, with a September 19, 2026 remediation due date for affected federal assets. Attribution posture: Cisco confirmed active exploitation but did not identify an actor or campaign.
Why this matters now
Cisco ISE sits in the identity and network-access control path. An unauthenticated attacker who bypasses its management interface can reach a privileged policy system that contains configuration and identity data and influences which users and devices gain network access. The absence of a configuration-dependent prerequisite increases the importance of complete asset discovery, including passive identity connectors, secondary nodes and non-production appliances.
Patching is necessary but insufficient because Cisco says successful exploitation may yield root privileges and allow evidence to be removed or hidden. Security leaders must separate remediation status from compromise status. A node upgraded to a fixed release may still require re-imaging, credential containment and policy validation if suspicious access-log or external network evidence exists.
The decision for security leaders
Identity and network leaders should run patching and incident triage as parallel workstreams. Patch deployment reduces future exposure; it does not answer whether an attacker already reached the management plane. Closure should require version evidence, node-by-node log review and external telemetry capable of detecting transfers or connections that appliance-level evidence may no longer show.
Any suspicious entry, unexplained administrative change or anomalous network transfer should move the node into incident handling. Cisco recommends re-imaging when malicious activity is suspected because root access may permit evidence removal. The recovery plan must also validate restored policies, administrator identities, certificates, integrations and secrets rather than assuming a configuration backup is inherently trustworthy.
Evidence of closure
- Asset register reconciled against every production, recovery, laboratory and passive-connector node.
- Version evidence showing each supported node on the applicable fixed release.
- Preserved access, firewall and network logs reviewed for the exploitation window.
- Documented re-image and credential-containment record for every suspicious node.
The Security.io assessment
The flaw warrants emergency handling because exploitation is confirmed, authentication is unnecessary and the affected system occupies a privileged identity-control position. The published dummyuser example is a useful starting point, not a complete signature. Its absence cannot prove that exploitation did not occur, particularly where root access could permit attackers to alter or remove local evidence.
An infrastructure access-control list is valuable for immediate containment where an upgrade cannot be completed safely, but it is an exception requiring an owner and expiry. The defensible end state is a supported fixed version plus evidence addressing pre-patch compromise. Organisations unable to produce either element should report the appliance as unresolved rather than remediated.
Questions for the morning meeting
- Where are all Cisco ISE and ISE-PIC nodes, including disaster-recovery and laboratory instances?
- Which nodes expose management or control-plane traffic beyond trusted administration networks?
- Has every node been reviewed for compromise independently of patch status?
- Can affected nodes be re-imaged without losing required identity and policy services?