Cisco ISE and ISE-PIC have an unauthenticated authentication bypass rated CVSS 10.0, and Cisco PSIRT confirms it is being exploited in the wild. Here is what to do this week, and what to do about the fact that this will happen again.
On September 16, 2026, Cisco published an ISE security advisory rated Critical, with a CVSS base score of 10.0. It is cisco-sa-ISE-ABP-VNSW7Tn5, covering CVE-2026-76460.
The vulnerability is an authentication bypass in a Cisco ISE API. An unauthenticated, remote attacker sends a crafted request to the affected API endpoint and gains unauthorized access to the appliance, bypassing the web-based management interface. A successful exploit may result in command execution with root privileges.
The vulnerability affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of device configuration. There is no feature you can disable to take yourself out of scope, and there is no workaround. Cisco does document a mitigation — infrastructure access control lists permitting only required management and control plane traffic to the appliance — but treats it as temporary until you upgrade. The fix is the patch.
CISA added to the Known Exploited Vulnerabilities catalog the same day. Under BOD 26-04, federal civilian agencies must prioritize remediation of KEV entries on publicly exposed assets that grant total control post-exploitation. This one qualifies.
The advisory does not arrive alone. Cisco published it simultaneously with the Cisco ISE Security Hardening Release: September 2026 (cisco-sa-hardening-ise-XU5EwX5T), which covers six further CVEs from an internal security review, two of them also scored 10.0 and two at 9.9.
| Running | First fixed release |
|---|---|
| ISE / ISE-PIC 3.5 | 3.5 Patch 4 |
| ISE / ISE-PIC 3.4 | 3.4 Patch 7 |
| ISE / ISE-PIC 3.3 | 3.3 Patch 12 |
| ISE / ISE-PIC 3.2 | 3.2 Patch 11 |
| ISE / ISE-PIC 3.1 | 3.1 Patch 12 |
| ISE 3.0 or earlier | No fix. 3.0 has reached End of Software Maintenance; you must upgrade to a supported release and patch it. |
Check Software Download for ISE for the current file for your release, and confirm the checksum before you move it anywhere.
Note releases 3.1 and 3.2 are in their Software Maintenance phase, and Cisco states that only Critical SIR fixes go into them. Patching those releases closes the bypass but does not bring you level with the full hardening set, and Cisco's own advice is to migrate to a release that includes it.
Patching closes the door but it does not evict anyone who already walked through it. Cisco's IoC guidance is specific, and it applies to every node in the deployment, not just the PAN:
admin# show logging application ise-kong/access.log | include <suspicious-username>./ise/logs/apigateway/access.log.<date>.gzIf you find anything, Cisco's recommendation is to re-image the affected nodes and restore from configuration backup.
The mechanics of applying an ISE patch are well documented. In practice the sequence looks like this:
Note that ISE patches are cumulative, but they are also release-bound: 3.3 Patch 12 does nothing for a 3.4 node. If your deployment spans releases, you are running multiple patch projects.
Before this advisory, you had a plan to patch ISE. Most organizations do. Then reality intervenes: the change board wants a rollback plan, the lab does not match production, the posture team needs a regression pass, the PSN in the second data center belongs to a different ops group. A 30-minute install becomes a three-to-six-week project, and while that project runs, the exposure stays open.
Ask yourself:
If the honest answers to questions like these are uncomfortable, the problem is not this advisory. The problem is that patching ISE is a project every time, and an actively exploited CVSS 10.0 does not wait for projects.
ModernISE Platform is Cisco ISE, delivered as a fully managed service in a dedicated, single-tenant enclave that ModernCyber operates. Patching, upgrades, certificate renewal, backups, and health assessment are part of the service. When Cisco publishes an advisory like this one, the response is our engineering task, executed with zero-downtime upgrades. It is not a change request on your board.
For most deployments, moving to ModernISE Platform is faster than planning, implementing, and testing patches on your own appliances.
Here is why:
Migrating to the ModernISE platform does not change your Cisco ISE licensing model, and it does not replace the policy decisions that are yours to make. What it removes is the InfraOps. The next advisory, the next upgrade, the next certificate expiry, and the next 2 a.m. rollback are ours. You do not patch faster; you do not patch at all.
If you want to scope a migration, or talk through the advisory itself, reach us at sales@moderncyber.com or ask your Cisco account manager about MODERN-SPLUS-SUB.
Sources