CVE-2026-76460 sits in an API endpoint on Cisco ISE and ISE Passive Identity Connector, and it doesn't care how the appliance is configured. BleepingComputer's report quotes Cisco's own advisory on the mechanics: "An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint." No credentials, no user interaction, no workaround Cisco is willing to recommend - the fix is the patch, applied across releases 3.1 through 3.5, or nothing. Cisco's Product Security Incident Response Team confirmed exploitation in the wild before the advisory went out, and CISA added the CVE to its Known Exploited Vulnerabilities catalog the same day, giving federal civilian agencies three days - until 19 September - to patch.
What root on an ISE box actually buys an attacker
It's worth being specific about why this particular product matters more than its category suggests. ISE isn't a file server or a marketing tool - it's the box that decides which devices and users get onto the network in the first place. Landon Rice, a researcher at VulnCheck, put it plainly in CyberScoop's coverage: "ISE devices enforce network access policy, so root access on the appliance lets an attacker modify that policy, extract stored credentials, delete logs" and move laterally into every segment ISE controls. An authentication bypass here isn't a foothold you build on - it's closer to handing over the building's access-control system along with the key to erase the visitor log afterward.
Two zero-days, unrelated, seven days apart
CVE-2026-76460 landed two days after Cisco patched CVE-2026-76461, an unrelated actively-exploited flaw in Secure Email Gateway. The near-consecutive CVE numbers invited an obvious question, and CyberScoop put it to Cisco directly. The answer was almost anticlimactic: "CVEs are assigned on a first-come, first-served basis, so consecutive numbering reflects assignment order rather than any relationship between the issues," a spokesperson said. That's a correct technical answer and a slightly unsettling one - it means the numbering is coincidence, but the underlying fact isn't: two independent security failures, in two independent products, both already being exploited, surfaced in the same week from the same vendor.
ISE has been a live target for over a year
This also isn't ISE's first appearance on the exploited list. CyberScoop's reporting notes active exploitation of ISE vulnerabilities going back to June 2025, including CVE-2025-20337 and CVE-2025-20281, both rated critical. Three critical, actively-exploited ISE bugs in fifteen months is a pattern, not a run of bad luck, and it argues for treating the platform itself - not just this one CVE - as a standing priority in any environment where it sits in front of network access decisions.
- Patch every Cisco ISE and ISE-PIC instance to the fixed release for its branch (3.1-3.5) immediately - there is no supported workaround for CVE-2026-76460.
- Pull the indicators of compromise Cisco published alongside the advisory and run them against ISE logs now, not after the next scheduled review.
- Because root access lets an attacker delete logs on the way out, don't rely solely on ISE's own audit trail to rule out prior compromise - cross-check against network access records from downstream switches and firewalls.
- If your ISE deployment has been exploited via any of the three critical bugs disclosed since June 2025, treat it as a standing high-value target and review its patch cadence separately from your general appliance fleet.
- Don't let "the CVE numbers are unrelated" read as "the risk is unrelated" - two unrelated exploited zero-days from one vendor in a week still means two incident response tracks running at once.
A perfect-10 CVSS score on the box that decides who gets network access is about as clear a priority signal as security tooling ever produces. If you'd like help auditing how exposed your identity and access infrastructure is to exploited-in-the-wild flaws like this one, email sales@halfteck.com.