CISA Mandates Federal Action on Actively Exploited Cisco ISE Authentication Flaw
A critical vulnerability tracked as CVE-2026-76460 (CVSS score 10.0) in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) is seeing active, in-the-wild exploitation. Insufficient authentication controls on an internal API endpoint allow unauthenticated remote attackers to bypass the web management interface and gain unauthorized access, potentially escalating to root privileges.
Because Cisco ISE serves as the primary Network Access Control (NAC) and policy decision point for enterprise networks, a compromise at this layer collapses core segmentation boundaries. An attacker with root-level access on ISE can manipulate RADIUS and TACACS+ policies, grant arbitrary access to segmented workloads, or tamper with device profiling. Furthermore, root execution enables adversaries to modify or conceal command history and access logs directly on the appliance, complicating incident response and forensic validation.
This incident highlights an ongoing vulnerability trend where network appliances and identity brokers—frequently excluded from traditional endpoint detection and response (EDR) agent coverage—become high-value entry points for sophisticated threat actors. Attackers increasingly exploit edge and identity infrastructure to establish initial footholds and move laterally before enterprise security operations centers (SOCs) detect anomalies.
In practice, security engineers must immediately apply Cisco's vendor patches across affected releases (including 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4). Because no permanent workaround exists, organizations that cannot patch instantly must deploy strict infrastructure access control lists (iACLs) and management plane ACLs, ensuring that ISE management endpoints are completely inaccessible from untrusted networks and internet-facing subnets. SOC teams should also inspect out-of-band network telemetry and external syslog streams for anomalous requests and unexpected user creation rather than relying solely on local node telemetry.
Read original source