Attackers breach Cisco ISE management interface through an API blind spot

Cisco's identity appliance is being hit through an API endpoint that never checked who was asking.

CSBadmin
2 Min Read

Cisco has confirmed that attackers are exploiting CVE-2026-76460, an authentication bypass in an API endpoint of Identity Services Engine, the appliance enterprises lean on to decide which people and devices may join the network.

The bug scores a perfect 10. Cisco says insufficient authentication control lets a remote, unauthenticated attacker send a crafted request and slip past the web-based management interface entirely. ISE and the ISE Passive Identity Connector are both affected at releases 3.0 through 3.5, whatever their configuration.

There are no workarounds. Fixed releases are 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11 and 3.1 Patch 12. Cisco notes that infrastructure access control lists restricting traffic to the appliance will block remote exploitation while upgrades are staged.

A successful hit hands attackers root, which matters because root lets them delete the very logs that would expose them. Cisco’s hunt guidance is to pull access.log on every node in the deployment and look for suspicious usernames. Any unexpected entry is grounds to suspect compromise, and the vendor recommends re-imaging affected nodes and restoring from configuration backup.

Because local logs may be gone, teams should cross-check network and firewall telemetry outside the device for odd uploads or downloads. CISA added the flaw to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies three days to patch under BOD 26-04.

Cisco has not named the attackers. It also shipped a batch of other ISE fixes, several of them found during internal testing with frontier AI models.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.