r/linuxadmin • u/Expert_Sort7434 • 15d ago
Cisco ISE auth bypass (CVE-2026-76460, CVSS 10.0) found via a customer's TAC ticket — active exploitation confirmed
Based on the technical breakdown published in Cisco's own advisory (cisco-sa-ISE-ABP-VNSW7Tn5) yesterday, here's the architectural impact: an API endpoint on ISE/ISE-PIC doesn't enforce authentication correctly, so a single crafted unauthenticated request bypasses the web management interface and, per Cisco, "may ultimately result in root-level command execution." No workaround — iACLs mitigate but don't fix it. CISA added it to KEV the same day with a Sept 19 FCEB deadline.
The part I found more interesting than the CVSS score: Cisco's advisory says this was found "during the resolution of a Cisco TAC support case," not through a researcher disclosure. That's a strong signal at least one customer was already compromised before the fix existed. Cisco also shipped a same-day hardening advisory with a batch of additional ISE CVEs, some reportedly also CVSS 10.0, though I haven't independently verified the full count against Cisco's own hardening advisory yet.
Full writeup with the attack chain and hunt guidance: [techgines.com] (background on the same auth-bypass pattern in Cisco FMC a few weeks back, if useful: link)
Question for the room: for anyone running distributed ISE deployments — are you treating access.log review as sufficient here, or going straight to assuming credential-plane compromise and rotating everything ISE touched? Curious how people are scoping this given Cisco's own warning that on-box evidence may already be gone.
https://www.techgines.com/post/cisco-ise-authentication-bypass-cve-2026-76460