What Cisco Actually Disclosed
Cisco published a security advisory on September 16, 2026 for CVE-2026-76460, an authentication bypass in Identity Services Engine and ISE Passive Identity Connector caused by insufficient authentication control on an API endpoint.
An unauthenticated remote attacker can send a specially crafted request to that endpoint and reach the device's web-based management interface without ever presenting valid administrator credentials. Cisco's Product Security Incident Response Team states plainly that it is already aware of active exploitation. The CVSS score is 10.0, the maximum the scale allows, reflecting an attack that needs no privileges, no user interaction, and can compromise confidentiality, integrity, and availability all at once.
Why ISE Specifically Is the Story
Identity Services Engine is Cisco's network access control product, the system that authenticates every device and user trying to join a corporate network and decides what they are allowed to touch once they are on it.
A flaw in a random application server is a problem for that server. A flaw in the system that grants network trust in the first place is a problem for everything behind it, because ISE is the gate other defenses assume is closed. An attacker who bypasses ISE's own authentication is not sneaking past a guard, they are walking through a door the guard was never posted at.
The Patch Table: Five Versions, Five Fixes
ISE and ISE-PIC releases 3.1 through 3.5 are all affected, and each needs its own specific patch rather than one blanket update.
| ISE / ISE-PIC version | Fixed release |
|---|---|
| 3.1 | Patch 12 |
| 3.2 | Patch 11 |
| 3.3 | Patch 12 |
| 3.4 | Patch 7 |
| 3.5 | Patch 4 |
An IT team should confirm the exact version running in its environment before patching, since applying the wrong patch number leaves the device exposed while looking updated.
No Workaround Is the Actual Headline
Cisco states directly that no workaround exists for CVE-2026-76460. The only mitigation on offer is restricting management and control-plane traffic to explicitly trusted systems using infrastructure access control lists, which reduces exposure but does not close the flaw itself.
That distinction matters for planning. A workaround buys time; an exposure-reduction measure buys a smaller window while the real fix, the patch, still has to happen. Any team telling itself the iACL step counts as remediation is choosing to stay vulnerable, just to a smaller set of sources.
The Clock That Actually Applies in the EU
CISA's Known Exploited Vulnerabilities catalog entry sets a September 19, 2026 deadline, but that date binds only US federal civilian agencies under Binding Operational Directive 26-04. It creates no legal obligation for a company in Germany, France, or anywhere else in the EU.
The clock that does apply is NIS2's, and it starts on a different trigger entirely: not a catalog date, but an actual significant incident. An essential or important entity that gets compromised through this flaw before patching faces an early-warning notification duty to its national CSIRT or competent authority within 24 hours of becoming aware, followed by a fuller incident notification within 72 hours. The US deadline is a convenient benchmark for urgency; the EU deadline, if this flaw is used against you, is the one with real consequences attached.
What to Do Before Anything Else Today
Confirm whether ISE or ISE-PIC runs anywhere in the environment, including instances a business unit or a remote team stood up without central IT's knowledge, since shadow deployments are exactly what a catalog-driven patch cycle misses.
Match the running version against the patch table above and apply the correct fix immediately. Where patching cannot happen today, restrict the management interface with an iACL as a stopgap, never as the plan. Then review access logs for the device for any sign the endpoint was already reached before the patch went in, since Cisco's own advisory confirms attackers found this one first.
Servola Journal
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: AI Is Compressing How Fast Spy Groups Share Exploits | Chrome Called It Medium. CISA Gave It 15 Days.



