Cisco ISE Zero-Day Authentication Bypass Threatens Enterprise Network Access Control Planes
Cisco confirmed active zero-day exploitation of CVE-2026-76460, a maximum-severity (CVSS 10.0) authentication bypass vulnerability affecting Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) across versions 3.1 through 3.5. The flaw resides in unauthenticated API endpoints where insufficient access controls permit remote attackers to submit specially crafted HTTP requests, completely circumventing web management controls to achieve administrative and potential underlying operating system command execution. Because active intrusions were identified, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog with an urgent remediation mandate.
This incident is critical for infrastructure and network security teams because ISE serves as the centralized policy, RADIUS/TACACS+ broker, and network access control (NAC) backbone for modern enterprise networks. Compromising an ISE deployment hands attackers full control over dynamic VLAN assignment, 802.1X posture assessments, network segmentation rules, and device trust telemetry. An attacker on an ISE node can modify network authorization policies, silently disable microsegmentation boundaries, and pivot laterally across entire software-defined network fabrics without triggering endpoint alerts.
This development fits into an aggressive, industry-wide targeting trend aimed directly at identity and network control plane appliances. Over recent cycles, sophisticated threat actors have shifted focus from individual host exploitation to central administrative appliances—such as network firewalls, PAM vaults, and identity controllers—which are frequently left running legacy code paths on internal management subnets. When the core management framework is subverted, the Zero Trust network assumptions built upon it collapse.
In practice, security engineers cannot rely on workarounds because none exist for this flaw. Infrastructure teams must immediately deploy the vendor security patches across all ISE primary and secondary nodes. Simultaneously, SecOps teams must inspect administrative access logs for anomalous API requests and verify that administrative interfaces, REST APIs, and PAN interfaces are strictly isolated from untrusted VLANs, contractor segments, and public-facing networks via dedicated out-of-band management ACLs and zero-trust bastion infrastructure.
Read original source