Skip to finding
§
High
Edge / RCE
Confirmed
CVE-2026-76460

Attackers are exploiting a Cisco ISE authentication bypass that can end in root command execution.

The path needs management-plane reachability but no credentials or user interaction.

Affects

Cisco Identity Services Engine and ISE Passive Identity Connector, network-access-control systems deployed as appliances or virtual machines.

What it enables

Unauthenticated root command execution on a network-access-control appliance

Attacker reaches an affected ISE or ISE-PIC management/API interface.→↓A crafted unauthenticated API request bypasses the web management interface.→↓The attacker obtains unauthorized appliance access.→↓Cisco says threat actors may obtain command execution with root privileges and can hide evidence.
Why this matters

Observed exploitation turns the management-plane authentication failure into a current root risk, although the interface must be reachable.

Detail and 5 sources
Required access

Network reachability to the Cisco ISE or ISE-PIC web/API management plane; no credentials or user interaction

Affected versions

ISE/ISE-PIC releases before 3.0 require migration to a supported fixed release, ISE/ISE-PIC 3.1 before Patch 12, ISE/ISE-PIC 3.2 before Patch 11, ISE/ISE-PIC 3.3 before Patch 12, ISE/ISE-PIC 3.4 before Patch 7, ISE/ISE-PIC 3.5 before Patch 4, ISE and ISE-PIC 3.0, ISE and ISE-PIC 3.1 before Patch 12, ISE and ISE-PIC 3.2 before Patch 11, ISE and ISE-PIC 3.3 before Patch 12, ISE and ISE-PIC 3.4 before Patch 7, ISE and ISE-PIC 3.5 before Patch 4, ISE/ISE-PIC 3.1 before 3.1 Patch 12, ISE/ISE-PIC 3.2 before 3.2 Patch 11, ISE/ISE-PIC 3.3 before 3.3 Patch 12, ISE/ISE-PIC 3.4 before 3.4 Patch 7, ISE/ISE-PIC 3.5 before 3.5 Patch 4, ISE/ISE-PIC releases before 3.1 require migration to a supported fixed release

A crafted unauthenticated API request bypasses the web management interface; Cisco says successful exploitation may then produce root command execution.

Cisco and the Canadian Cyber Centre identify fixed releases, and both record the exploitation.

Evidence
Cisco advisory confirms unauthenticated bypass, possible root execution, fixes and active exploitationCanadian Cyber Centre independently records active exploitation and fixed releases
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 19, 2026