Cisco disclosed nine vulnerabilities in its Identity Services Engine (ISE) on September 16, 2026, including multiple critical-severity flaws currently under active exploitation. The Cisco PSIRT advisory confirms that CVE-2026-76460, an unauthenticated REST API authentication bypass, carries a CVSS score of 10.0 and is being leveraged by attackers in the wild.
The discovery of CVE-2026-76460 occurred during the resolution of a Cisco Technical Assistance Center (TAC) support case. This detail confirms that at least one enterprise environment was already compromised before the vulnerability was identified and reported. The flaw allows unauthenticated attackers to bypass authentication mechanisms entirely, granting them unauthorized access to the platform.
Two additional critical vulnerabilities were disclosed alongside the primary bypass. CVE-2026-20305 and CVE-2026-20306 are command injection flaws in diagnostic tools and the REST API, respectively. Both carry a CVSS score of 9.1. While these require authentication, they allow an attacker to escalate privileges to root. These vulnerabilities were reported by researchers at STAR Labs SG, who previously identified a critical command injection flaw in the same platform in June 2026.
The September 16 disclosure was not limited to these three flaws. A separate advisory released the same day detailed six additional vulnerabilities. This batch includes CVE-2026-76423, another CVSS 10.0 REST API authentication bypass, and CVE-2026-76424, an arbitrary file access vulnerability that leads to remote code execution.
Cisco ISE serves as the central nervous system for enterprise network access control. It manages 802.1X authentication, device profiling, and posture assessment for wired, wireless, and VPN connections. By compromising this platform, an attacker gains the ability to subvert the very controls intended to secure the network perimeter. The platform designed to enforce Zero Trust and validate device health has become the primary vector for unauthenticated, full-network access.
This event follows a recurring structural pattern observed in recent security disclosures. The compromise of identity infrastructure as an attack surface mirrors the recent Delinea Secret Server incident, where a privileged access management platform faced four critical CVEs in two weeks. Similar patterns have emerged in the Cisco ESA management plane, the ShieldCrash incident, OpenAI back-channel vulnerabilities, and SonicWall SMA1000 appliance compromises.
The urgency of this disclosure is compounded by the lack of available workarounds for most of the identified vulnerabilities. Cisco has issued patches for supported versions, including 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Organizations running these versions must prioritize immediate upgrades to mitigate the risk of exploitation.
The ISE-PIC release 3.4 remains the final supported version for that specific product line, which has reached its end-of-sale status. This adds a layer of complexity for organizations managing legacy infrastructure that may no longer receive the same level of security support or feature updates as the core ISE platform.
The concentration of nine critical vulnerabilities in a single identity platform highlights a systemic risk. When the infrastructure responsible for verifying user and device identity is itself vulnerable to unauthenticated bypass, the security model of the entire enterprise is effectively neutralized. Security professionals must treat these identity platforms not as static security tools, but as high-value, high-risk assets that require the same rigorous patching and monitoring as the most sensitive production servers.
The active exploitation of CVE-2026-76460 serves as a reminder that identity infrastructure is a primary target for sophisticated actors. The transition from perimeter-based security to identity-centric models has shifted the attack surface, making the platforms that manage that identity the most critical points of failure in the modern enterprise.
