CISA KEV: Cisco ISE Privileged API Flaw Allows Unauthenticated Management Bypass
Medium · CISA Known Exploited Vulnerabilities ·
Key points
- CISA's Known Exploited Vulnerabilities catalog lists a Cisco ISE and ISE-PIC flaw.
- The issue involves incorrect use of privileged APIs.
- An unauthenticated remote attacker could bypass the web management interface and gain unauthorized access.
- CISA directs agencies to apply vendor mitigations under BOD 26-04.
- Verify exposure and discontinue use if mitigations are unavailable.
CISA's Known Exploited Vulnerabilities catalog has flagged a vulnerability affecting Cisco Identity Services Engine and Cisco ISE Passive Identity Connector. The flaw is described as an incorrect use of privileged APIs, and the stated risk is that an unauthenticated, remote attacker could bypass the web-based management interface and gain unauthorized access to the affected device. The provided record links to CVE-2026-76460, but the feed's CVE field is empty, so the identifier should be confirmed against Cisco and NVD advisories.
Organizations using Cisco ISE for network access control, identity management, or ISE-PIC for passive identity are potentially affected. In K-12 environments, these systems may support wired and wireless access, guest onboarding, BYOD controls, and district-wide authentication policy enforcement. Any ISE deployment with a management interface reachable from untrusted networks deserves immediate review.
Because ISE is an identity and access control platform, unauthorized access to the device can undermine confidence in authentication and authorization decisions. Even if the exact downstream impact is not yet clear from the available facts, a bypass of the management interface is significant: it could expose administrative functions to an attacker who has not authenticated. This raises the risk for districts that rely on ISE to enforce network segmentation or user policy.
CISA's required action is to apply mitigations according to vendor instructions, consistent with BOD 26-04 risk-based patching and forensics triage requirements. If mitigations are unavailable for a cloud service, agencies should discontinue use of the product. Stakeholders are also expected to evaluate each asset's internet exposure and follow BOD 26-04 patching guidance. The KEV listing indicates known exploitation, so prioritization should reflect that urgency.
What to watch: Cisco's advisory for fixed versions or workarounds, confirmation of the CVE identifier, and any updates to the CISA KEV entry. Administrators should limit management interface access to trusted networks or VPN, review logs for suspicious administrative activity, and track whether their ISE deployments are internet-facing. Until mitigations are applied, exposed systems should be treated as high risk.
What to do now
- Inventory all Cisco ISE and ISE-PIC instances, including versions, management interface exposure, and business criticality.
- Apply Cisco's recommended mitigations or fixed software immediately, prioritizing any internet-facing or high-value deployments.
- If mitigations are unavailable, isolate or discontinue use of the affected system in line with CISA BOD 26-04 guidance.
- Restrict web-based management access to trusted admin networks or VPN and remove direct public exposure.
- Review ISE logs for unusual admin logins, configuration changes, or access attempts during the possible exploitation window.
- Verify CVE-2026-76460 in Cisco and NVD advisories, and monitor the CISA KEV entry for updates.
- Align patching and triage activities with BOD 26-04 risk-based requirements and CISA forensics triage guidance.
Original source
Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.