CYBERSECURITY

Cisco ISE Nine Critical Vulnerabilities: Identity Infrastructure Under Attack

Cisco disclosed nine vulnerabilities in its Identity Services Engine on September 16, 2026, including CVE-2026-76460 — an unauthenticated REST API authentication bypass with a CVSS 10.0 score that is being actively exploited in the wild.

Cisco ISE network security dashboard Cybersecurity

Cisco's September 16 security advisory revealed a concentrated cluster of critical flaws in Identity Services Engine, the platform that enterprise networks rely on to verify user and device identity before granting access. The disclosure included CVE-2026-76460, an unauthenticated REST API authentication bypass carrying a CVSS base score of 10.0 — the maximum possible rating — and Cisco confirmed it is being leveraged by attackers in the wild.

Two additional critical flaws raise the stakes further. CVE-2026-20305 and CVE-2026-20306 are command injection vulnerabilities in diagnostic tools and the REST API respectively, both carrying CVSS scores of 9.1. While these require authentication, they allow an attacker to escalate privileges to root on the affected system. Both were reported by researchers at STAR Labs SG, who had previously identified a critical command injection flaw in the same platform in June 2026.

The September 16 disclosure was not limited to these three flaws. A separate advisory released the same day detailed six additional vulnerabilities, including CVE-2026-76423 — another CVSS 10.0 REST API authentication bypass — and CVE-2026-76424, an arbitrary file access vulnerability that leads to remote code execution. The complete picture is a platform with multiple independent paths to full compromise, several of them reachable without authentication.

The structural pattern here is the story. Identity infrastructure has become the primary target for sophisticated actors because the transition from perimeter-based security to identity-centric models has shifted the attack surface. When the platform responsible for verifying who can access what is itself vulnerable to unauthenticated bypass, the security model of the entire enterprise is effectively neutralized. This mirrors the recent Delinea Secret Server incident, where a privileged access management platform faced four critical CVEs in two weeks.

For organizations running Cisco ISE, the priority is clear: patch internet-reachable FMC and ISE instances immediately, treat this as a sprint rather than a scheduled update window, and assume that any instance exposed to the internet may already be under investigation by attackers. The concentration of nine critical vulnerabilities in a single identity platform is a systemic risk that warrants an emergency patch cycle, not a normal maintenance cadence.

This disclosure also reinforces a broader 2026 trend: the platforms that manage identity and access are now the most critical points of failure in the modern enterprise, and they are receiving sustained attention from attackers who understand that compromising identity infrastructure is more valuable than compromising any single endpoint.

Cybersecurity • Cisco • Identity • Zero Trust • CVE-2026-76460