9/22/2026 • Security
Cisco ISE Zero-Day: The Gatekeeper Was Bypassed Before the Patch
A maximum-severity, unauthenticated authentication bypass in Cisco Identity Services Engine (CVE-2026-76460) was already being exploited when Cisco disclosed it — found only because a customer's network had been compromised. Here's what happened and what to check.
On 16 September 2026, Cisco confirmed the kind of thing every network admin dreads: attackers had already broken into Cisco Identity Services Engine (ISE) deployments through an authentication bypass before a patch existed to stop them. ISE is the software that decides who and what is allowed onto a corporate network — device checks, guest Wi-Fi, RADIUS/802.1X, the lot. The flaw needs no login at all, carries a perfect CVSS 10.0, and the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalogue the same day, with a three-day patch deadline for US federal agencies. If ISE controls who gets onto your network, this is one to act on now.
What happened, in plain English
The headline issue is CVE-2026-76460, published in its own advisory (cisco-sa-ISE-ABP-VNSW7Tn5). The cause is an API endpoint with insufficient authentication control: a remote attacker sends a crafted request to it, no credentials required, and gains unauthorised access to the device by bypassing the web-based management interface entirely. Cisco says a successful exploit can lead to command execution with root privileges — full control of the box. Cisco hasn't disclosed who is behind the attacks or how many organisations were hit, only that it's "aware of active exploitation." One detail worth taking seriously: because the access is root-level, Cisco warns attackers may be able to remove or hide evidence on the device itself, which is why organisations are being told to check external firewall and network logs rather than trust the box's own logs alone.
According to reporting on the disclosure, Cisco found this flaw while working a customer's technical support case — meaning it came to light because someone had already been broken into, not because Cisco caught it first.
The affected products are Cisco ISE and ISE Passive Identity Connector (ISE-PIC), releases 3.1 through 3.5 (3.0 is already end-of-support and isn't getting a fix — migrate off it). There's no workaround. The fixes are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Worth flagging for anyone still on ISE-PIC specifically: it's reached end-of-sale, and 3.4 is the last release it'll ever get — one more reason to be current rather than several versions behind.
Cisco published a second, related advisory the same day covering six further ISE/ISE-PIC vulnerabilities it found through its own internal hardening review (CVE-2026-20130, -20192, -20194, -20234, -20237 and -20287), grouped by underlying bug class rather than exact same weakness. The nuance matters here: two of the six (-20130 and -20192) are also unauthenticated and rated a full 10.0, but the other three require an attacker to already hold valid — in most cases high-level — credentials on the box, which is a meaningfully smaller attack surface even at a high CVSS score. None of these six are confirmed as exploited; only CVE-2026-76460 is on the KEV list.
Why it matters
ISE isn't just another appliance sitting at the edge — it's the thing that grants trust to everything else on the network. Bypass it, and in principle you're not just getting a foothold, you're standing at the desk that hands out the passes. That's what makes an authentication-bypass flaw in a network access control (NAC) platform a different order of problem to, say, a bug in a single router: the blast radius is every device the platform was supposed to be gatekeeping.
The honest bit
We sell and recommend Cisco Meraki gear, so it'd be easy to go quiet on a Cisco story. We won't — no vendor is immune, including the ones we like, and we said the same thing when we covered Cisco's own end-of-life RV routers.
To Cisco's credit, the six-CVE hardening bundle is what a genuinely proactive vendor looks like: they went looking for problems in their own product before anyone else found them, and shipped fixes for issues nobody outside Cisco had spotted. But the sobering half of this story is that their own review didn't catch the one that actually mattered — the zero-day making headlines was found because a customer had already been compromised. "This vendor takes security seriously" and "you were safe until today" turned out to be two different claims. We made a near-identical point recently about SonicWall's SMA1000 zero-days, where the patch also arrived after the attack — it's becoming a familiar shape for edge and identity infrastructure specifically.
One genuine, non-sales difference worth knowing: cloud-managed platforms take the "did someone remember to patch this specific on-prem box" risk off your plate, because fixes get pushed automatically rather than waiting on someone logging in. We've written about why that model keeps improving after purchase — not a pitch, just a real difference in how the burden falls.
What we'd suggest you actually do
- If you run Cisco ISE or ISE-PIC (3.1 through 3.5): patch now. Go to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 or 3.5 Patch 4 as applicable. If you're on 3.0, it's unsupported — plan a migration, because no fix is coming for that version.
- Don't assume "patched" means "clean." Because this was exploited before disclosure, and Cisco itself warns on-box evidence may have been tampered with, check external firewall and network logs for unusual traffic to or from the appliance, rather than relying solely on its own logs.
- Keep the management interface off the open internet. Restrict ISE administration to internal management networks only — this class of flaw is far less dangerous to a box nobody outside your network can even reach.
- Take the same six-CVE hardening bundle seriously, even without a KEV listing. If you're behind on ISE patches generally, this release is a good forcing function to catch up.
- Know your identity infrastructure. NAC, RADIUS and SSO/identity systems tend to be set up once and quietly forgotten — write down what you're running and who owns patching it, the same advice we'd give for any forgotten box quietly sitting at the edge.
The friendly takeaway
This isn't "Cisco bad" — it's a reminder that the system trusted to decide who belongs on your network is exactly the system attackers most want to own, and that even a vendor doing the right things internally can still be beaten to the punch by whoever finds the bug first. Patch it, check your logs rather than just the box's own, and keep an eye on what's quietly gatekeeping your network day to day.
As always, this post is part of us keeping watch so you don't have to. If you'd like a second pair of eyes on your network access setup — what's exposed, what's patched, what's quietly overdue — get in touch. No obligation, no hard sell.
References
- Cisco Security Advisory — Cisco Identity Services Engine Authentication Bypass Vulnerability (cisco-sa-ISE-ABP-VNSW7Tn5)
- Cisco Security Advisory — Cisco Identity Services Engine Hardening Release: September 2026 (cisco-sa-hardening-ise-XU5EwX5T)
- NVD — CVE-2026-76460 (CVSS 10.0, unauthenticated)
- CISA — Known Exploited Vulnerabilities Catalog (CVE-2026-76460, added 16 September 2026)
- NVD — CVE-2026-20130, CVE-2026-20192, CVE-2026-20194, CVE-2026-20234, CVE-2026-20237, CVE-2026-20287
- The Hacker News — Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks