ModernCyber Blog

CVE-2026-76460: Patch ISE Now — Then Decide Whether You Ever Want to Patch Again

Written by ModernCyber | Sep 21, 2026, 10:47:58 PM

Cisco ISE and ISE-PIC have an unauthenticated authentication bypass rated CVSS 10.0, and Cisco PSIRT confirms it is being exploited in the wild. Here is what to do this week, and what to do about the fact that this will happen again.

The advisories

On September 16, 2026, Cisco published an ISE security advisory rated Critical, with a CVSS base score of 10.0. It is cisco-sa-ISE-ABP-VNSW7Tn5, covering CVE-2026-76460.

The vulnerability is an authentication bypass in a Cisco ISE API. An unauthenticated, remote attacker sends a crafted request to the affected API endpoint and gains unauthorized access to the appliance, bypassing the web-based management interface. A successful exploit may result in command execution with root privileges. 

The vulnerability affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of device configuration. There is no feature you can disable to take yourself out of scope, and there is no workaround. Cisco does document a mitigation — infrastructure access control lists permitting only required management and control plane traffic to the appliance — but treats it as temporary until you upgrade. The fix is the patch.

CISA added to the Known Exploited Vulnerabilities catalog the same day. Under BOD 26-04, federal civilian agencies must prioritize remediation of KEV entries on publicly exposed assets that grant total control post-exploitation. This one qualifies.

The advisory does not arrive alone. Cisco published it simultaneously with the Cisco ISE Security Hardening Release: September 2026 (cisco-sa-hardening-ise-XU5EwX5T), which covers six further CVEs from an internal security review, two of them also scored 10.0 and two at 9.9. 

Fixed releases

Running First fixed release
ISE / ISE-PIC 3.5 3.5 Patch 4
ISE / ISE-PIC 3.4 3.4 Patch 7
ISE / ISE-PIC 3.3 3.3 Patch 12
ISE / ISE-PIC 3.2 3.2 Patch 11
ISE / ISE-PIC 3.1 3.1 Patch 12
ISE 3.0 or earlier No fix. 3.0 has reached End of Software Maintenance; you must upgrade to a supported release and patch it.

 

Check Software Download for ISE for the current file for your release, and confirm the checksum before you move it anywhere.

Note releases 3.1 and 3.2 are in their Software Maintenance phase, and Cisco states that only Critical SIR fixes go into them. Patching those releases closes the bypass but does not bring you level with the full hardening set, and Cisco's own advice is to migrate to a release that includes it.

Before you patch, check whether you are already compromised

Patching closes the door but it does not evict anyone who already walked through it. Cisco's IoC guidance is specific, and it applies to every node in the deployment, not just the PAN:

  1. On each node, search the API gateway access log for usernames that should not exist:
    admin# show logging application ise-kong/access.log | include <suspicious-username>
  2. For older rotated logs, collect a support bundle with include debug logs selected and shared-key encryption, then decrypt and review ./ise/logs/apigateway/access.log.<date>.gz
  3. Cross-check firewall and network logs outside the ISE nodes for unexpected outbound uploads from ISE or downloads from unfamiliar IPs. Root access means the attacker can clean up the evidence on the box itself.

If you find anything, Cisco's recommendation is to re-image the affected nodes and restore from configuration backup.

How to patch ISE

The mechanics of applying an ISE patch are well documented. In practice the sequence looks like this:

  1. Read the patch release notes first. Every ISE patch has open and resolved caveats. Know which ones touch your feature set (TACACS+, pxGrid, posture, guest, SXP) before you commit to a window.
  2. Take full backups. Configuration and operational backups to an external repository.
  3. Install from the primary PAN. In the GUI, navigate to Administration > System > Maintenance > Patch Management > Install. Click Browse and choose the patch file that was downloaded from Cisco.com.. Then click Install to install the patch. The primary PAN patches first, then the patch rolls to the remaining nodes in the deployment one at a time. Each node restarts its application services during installation.
  4. Verify on every node. Confirm the patch version in the dashboard by clicking on the user or account icon and selecting About ISE and Server. Confirm replication is healthy and all nodes are back in sync.
  5. Test what matters. 802.1X and MAB authentications, TACACS+ device administration, guest flows, posture, and any pxGrid subscribers. 
  6. Know your rollback. ISE supports patch rollback from the same Patch Management page. 

Note that ISE patches are cumulative, but they are also release-bound: 3.3 Patch 12 does nothing for a 3.4 node. If your deployment spans releases, you are running multiple patch projects. 

The questions the advisory should make you ask

Before this advisory, you had a plan to patch ISE. Most organizations do. Then reality intervenes: the change board wants a rollback plan, the lab does not match production, the posture team needs a regression pass, the PSN in the second data center belongs to a different ops group. A 30-minute install becomes a three-to-six-week project, and while that project runs, the exposure stays open.

Ask yourself:

  • How long did it take to confirm which release and patch level every node was running?
  • Do you have a maintained lab that matches production closely enough to trust a regression pass?
  • How long is the gap between "CISA added it to KEV" and "the change is approved"?
  • Who owns the patch when the deployment spans 3.3 and 3.4, or multiple business units?
  • If you had to re-image a node tomorrow, how confident are you in the restore?
  • How many times has this cycle repeated since you deployed ISE, and how many times will it repeat before you replace the hardware?

If the honest answers to questions like these are uncomfortable, the problem is not this advisory. The problem is that patching ISE is a project every time, and an actively exploited CVSS 10.0 does not wait for projects.

Migrating is faster than patching

ModernISE Platform is Cisco ISE, delivered as a fully managed service in a dedicated, single-tenant enclave that ModernCyber operates. Patching, upgrades, certificate renewal, backups, and health assessment are part of the service. When Cisco publishes an advisory like this one, the response is our engineering task, executed with zero-downtime upgrades. It is not a change request on your board.

For most deployments, moving to ModernISE Platform is faster than planning, implementing, and testing patches on your own appliances.

Here is why:

  • Activation to ISE UI is 60–90 minutes, not a change window weeks out. The platform builds the enclave, the nodes, and the certificates; you bring your license (BYOL) and your policy.
  • Migration from an existing ISE cluster is a supported path. Your policy sets, authorization profiles, network device inventory, and certificates come over. The work is cutover planning and re-pointing network devices to new PSNs, which is the same work you would do to add a PSN today.
  • The new environment is already on a fixed release. You do not patch it before you cut over to it. Your legacy cluster keeps serving until the last switch is re-pointed, and then it is decommissioned rather than patched.
  • It is on the Cisco Global Price List. ModernISE Platform is orderable through Cisco SolutionsPlus under MODERN-SPLUS-SUB, on the same Cisco paper you already have in place. Your Cisco account team or partner can quote it today.

Migrating to the ModernISE platform does not change your Cisco ISE licensing model, and it does not replace the policy decisions that are yours to make. What it removes is the InfraOps. The next advisory, the next upgrade, the next certificate expiry, and the next 2 a.m. rollback are ours. You do not patch faster; you do not patch at all.

If you want to scope a migration, or talk through the advisory itself, reach us at sales@moderncyber.com or ask your Cisco account manager about MODERN-SPLUS-SUB.

Sources