CVE-2026-76460: Cisco ISE Privileged API Flaw Added to CISA KEV — Patch by September 19, 2026
CISA added CVE-2026-76460, an unauthenticated remote access bypass in Cisco Identity Services Engine (ISE) and ISE-PIC, to the Known Exploited Vulnerabilities catalog on 2026-09-16. Federal patch deadline: 2026-09-19.

CVE-2026-76460: Cisco ISE Privileged API Flaw Added to CISA KEV — Patch by September 19, 2026
TL;DR
CVE-2026-76460, an incorrect use of privileged APIs flaw in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-16. The vulnerability allows an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Federal civilian agencies must apply mitigations per vendor instructions by 2026-09-19; all other organizations should treat this as an emergency patch given the short KEV window and the identity-control role ISE plays in the network.
What is this vulnerability?
- CVE ID: CVE-2026-76460
- Vendor / Product: Cisco / Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC)
- Vulnerability name: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
- Weakness class: CWE-648 — Incorrect Use of Privileged APIs
- Impact: An unauthenticated, remote attacker could gain unauthorized access to the affected device by bypassing the web-based management interface.
- CISA KEV status: Yes — added 2026-09-16
- CISA due date: 2026-09-19
- Known ransomware use: Unknown per CISA KEV entry
- Required action (CISA): Apply mitigations in accordance with vendor instructions, consistent with BOD 26-04 Prioritizing Security Updates Based on Risk and the associated Forensics Triage Requirements guidance. Where mitigations are unavailable, follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product.
Because ISE is a policy decision point for network access control, an authentication bypass on the management interface is not a routine patch — it is a potential trust-boundary failure. Treat any exposed ISE node as a candidate for compromise review, not just remediation.
KEV vs CVSS vs EPSS
| Signal | What it measures | How to use it for this CVE |
|---|---|---|
| CISA KEV | Confirmed in-the-wild exploitation, with a binding remediation deadline for federal agencies | Authoritative here: CVE-2026-76460 is listed, added 2026-09-16, due 2026-09-19. Use it to justify emergency change windows and executive escalation. |
| CVSS | Intrinsic technical severity of the flaw (base score, exploitability, impact) | Not provided in the source intel for this CVE — do not cite a score. The unauthenticated, remote, management-interface-bypass description is sufficient to prioritize regardless of score. |
| EPSS | Probability the vulnerability will be exploited in the wild in the near term | Not provided in the source intel for this CVE. KEV listing already confirms exploitation, so EPSS is secondary for prioritization here. |
Bottom line: KEV status is the deciding signal. Do not wait on a CVSS or EPSS lookup to open a change ticket.
Step-by-step remediation
- Inventory. Query your CMDB, asset scanners, and network telemetry for all Cisco ISE and ISE-PIC deployments — including virtual appliances, distributed deployment nodes (PAN, PSN, MnT), and any passive identity connectors. Confirm software versions against the Cisco advisory.
- Assess exposure. Determine which ISE management interfaces are reachable from untrusted networks, including the internet. Per CISA, stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Patch or mitigate. Apply the mitigations in the Cisco security advisory (
cisco-sa-ISE-ABP-VNSW7Tn5) in accordance with vendor instructions. If mitigations are unavailable for a given deployment, follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product. - Hunt for prior compromise. Because the flaw permits unauthenticated access via the management interface, review ISE admin audit logs, authentication logs, and configuration-change history for anomalous administrative activity in the window before patching. Follow CISA's Forensics Triage Requirements guidance referenced in the KEV entry.
- Verify. After patching, confirm the running version on every node, re-scan the management interface for exposure, and validate that administrative access controls behave as expected.
- Close the ticket with evidence. Record patch version, node inventory, exposure assessment, log-review outcome, and the change record ID. Retain this for BOD 26-04 compliance evidence if you are a federal agency.
FAQ
Is CVE-2026-76460 in CISA KEV? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-16, which means exploitation in the wild has been confirmed.
What is the CISA due date for CVE-2026-76460? The remediation due date is 2026-09-19 — three days after the KEV addition. That is an unusually tight window; plan for an emergency change.
Is this vulnerability internet-facing / remotely exploitable? The flaw is described as remotely exploitable by an unauthenticated attacker who can bypass the web-based management interface. CISA explicitly directs stakeholders to evaluate each asset's internet exposure. Even if your ISE management plane is segmented, verify that assumption with telemetry rather than documentation.
Is CVE-2026-76460 tied to ransomware? CISA's KEV entry lists known ransomware use as Unknown. Absence of a confirmed ransomware link does not lower urgency — KEV listing alone confirms active exploitation.
What is CWE-648 and why does it matter here? CWE-648 (Incorrect Use of Privileged APIs) means the product misuses privileged API calls in a way that lets an attacker exceed intended authorization. In an identity platform like ISE, that can translate directly into unauthorized administrative access.
Does this affect Cisco ISE-PIC as well as ISE? Yes. The advisory covers both Cisco Identity Services Engine and Cisco ISE Passive Identity Connector.