SECURITY Signal 47
Cisco ISE and ISE-PIC face active exploitation of CVE-2026-76460 authentication bypass
An unauthenticated API bypass in Cisco ISE and ISE-PIC allows remote attackers to gain root-level command execution.
The flaw carries a maximum CVSS 10.0 rating and has no safe workarounds, requiring immediate patching. Because root access allows attackers to erase local logs, administrators cannot rely on appliance records to confirm if a system was compromised.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Attackers can bypass the web-based management interface without credentials or user interaction.
Cisco ISE 3.0 is unsupported and requires a full migration to a newer release to resolve the flaw.
Infrastructure access control lists are listed as a mitigation for containment but not as a final solution.
THE READ
What the cluster adds up to.
CVE-2026-76460 stems from insufficient authentication controls on a management API endpoint. A crafted request allows an unauthenticated remote attacker to bypass the management interface and obtain root privileges. This level of access enables the modification of the appliance and the potential removal of exploitation evidence from local logs.
Remediation requires upgrading to specific patch levels across different release trains, such as Patch 12 for version 3.13.1 or Patch 11 for 3.23.2. However, users on ISE 3.0 face a higher cost of adoption because that version has reached end of software maintenance. These users must migrate to a supported release, which requires validating hardware capacity and configuration compatibility.
Detection is complicated by the fact that root access allows attackers to hide their tracks. Cisco advises inspecting access.log for suspicious usernames like dummyuser across all nodes in a distributed deployment. To verify integrity, responders must corroborate these local records with external network and firewall logs to identify unexpected data transfers to external IP addresses.
If a compromise is suspected, applying the patch is insufficient as it only prevents future attacks. Cisco recommends reimaging affected nodes and restoring configuration backups. For immediate containment, organizations with externally reachable management paths are advised to use infrastructure access control lists to limit control-plane traffic.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗