Threat Landscape

Cisco ISE CVE-2026-76460 is CVSS 10. Identity is the blast radius.

Unauth API bypass on ISE/ISE-PIC. CVSS 10. Active exploit. CISA KEV due Sep 19. No workarounds; iACL bandage. Patch 3.1P12 / 3.2P11 / 3.3P12 / 3.4P7 / 3.5P4. What does patch SLA mean on the NAC plane?

Sep 17, 2026 · 5 min read

When the identity control plane fails, the firewall policy is theater. Cisco just proved it again.

On September 16 Cisco published advisory cisco-sa-ISE-ABP-VNSW7Tn5 for CVE-2026-76460, an authentication bypass in an API of Cisco Identity Services Engine. CVSS base score: 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Insufficient authentication control on an API endpoint lets an unauthenticated, remote attacker send a crafted request and bypass the web-based management interface. Both Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC) are affected, regardless of device configuration. That is not a misconfig story. That is a product-plane story.

Cisco’s Product Security Incident Response Team confirms active exploitation. The vulnerability was found during resolution of a Cisco TAC support case — which is how many of the worst control-plane bugs surface: a customer ticket, then a PSIRT scramble. There are no workarounds. Cisco’s temporary mitigation is infrastructure access control lists (iACLs) that allow only required management and control-plane traffic destined to the affected device. Patch is the remediations path. Mitigation is a bandage until the upgrade lands.

Fixed releases, per the advisory: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4. Release 3.0 is end of software maintenance; migrate. Same-day CISA added CVE-2026-76460 to the Known Exploited Vulnerabilities catalog (alongside Acronis CVE-2026-87886). Date added: 2026-09-16. Due date for FCEB agencies under BOD 26-04: 2026-09-19. SecurityWeek frames that as a three-day federal patch window. Private enterprises do not get a free pass because BOD 26-04 is federal-scoped — CISA explicitly encourages all organizations to prioritize KEV.

Blast radius is why this is a Featured essay, not a ticker blurb. Successful exploitation can yield command execution with root privileges, Cisco warns. Post-compromise, threat actors may remove or hide on-box indicators. Hunt guidance: review ise-kong/access.log (and support-bundle API gateway access logs) for suspicious usernames on every node in a distributed deployment; cross-check network and firewall logs outside the device for unexpected uploads or downloads. If compromise is suspected, Cisco recommends re-imaging affected nodes and restoring from configuration backup. Victim count: Undisclosed.

POV: NAC and identity appliances are force multipliers. Own ISE and you own who gets on the network, what policies bind, and which sessions look legitimate. A CVSS 10 unauthenticated API bypass on that plane is not “another Cisco bug.” It is a question about what “patch SLA” means when the blast radius is the control plane itself. 72-hour KEV clocks are for federal compliance. Enterprise reality is change windows, HA pairs, and the quiet fear that the box already answered a crafted request last week. Patch 3.1P12 / 3.2P11 / 3.3P12 / 3.4P7 / 3.5P4. Assume exposed management interfaces are high priority. Sources: Cisco PSIRT Sep 16, CISA KEV Sep 16 (due Sep 19), and SecurityWeek Sep 17.

Underwrite sheet — sourced only: CVE-2026-76460; CVSS 10.0; unauth remote API auth bypass on ISE + ISE-PIC any config (Cisco); no workarounds; iACL mitigation (Cisco); active exploitation (PSIRT); found via TAC case; fixed 3.1P12 / 3.2P11 / 3.3P12 / 3.4P7 / 3.5P4; root possible; IoCs may be wiped; hunt access.log every node; re-image if suspected (Cisco); CISA KEV added 2026-09-16, due 2026-09-19 (CISA catalog / SecurityWeek); victim count Undisclosed. Identity is the blast radius. Patch SLA is the question.

Sources