endoflife.ai
Cisco ISE EOS Edge Device List Exploited & Unpatchable EOL Watch

Cisco ISE CVE-2026-76460: 3.1 to 3.5 Patched, 3.1 and 3.2 End Nov 3

By Scott Bissett  ·  Published: September 16, 2026  ·  EOL Watch — news analysis  ·  Read at Cisco's advisory, Cisco's CVE record and CISA's catalog on the day of listing; lifecycle dates from Cisco's per-release ISE end-of-life bulletins.

The management interface is the target, and no login is needed. Cisco's advisory cisco-sa-ISE-ABP-VNSW7Tn5, published on the day CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog, September 16, 2026, describes an API endpoint in Cisco Identity Services Engine and the ISE Passive Identity Connector with, in Cisco's words, "insufficient authentication control on an API endpoint". An unauthenticated, remote attacker who sends a crafted request to it bypasses the web-based management interface and gains unauthorized access to the appliance. CVSS 10.0, the top of the scale. No workarounds. Cisco says it found the flaw during the resolution of a TAC support case, and the advisory states plainly: "The Cisco PSIRT is aware of active exploitation of this vulnerability."

ISE is the box that decides who gets onto the network. It holds the RADIUS and TACACS+ policy, the device certificates, the posture rules and the administrator accounts for the switches and firewalls it talks to. An attacker with unauthorized access to it is not on one server; they are at the front desk with the master key. That is why CISA's entry carries the forensic-triage flag, and why this is the third ISE entry in CISA's catalog: the earlier two, CVE-2025-20281 and CVE-2025-20337, were added on July 28, 2025.

The deadline and the extra requirement. CISA's due date for federal agencies is September 19, 2026, three days after listing. The entry also carries a forensic-triage flag under CISA's Binding Operational Directive 26-04: patching alone does not close it. Before you trust the appliance again, check it for compromise: the administrator accounts, the API access and audit logs, and every policy change on the deployment since the exposure window opened. An identity server that has been reached without a login can have been altered without a login.
Quick answer: Cisco Identity Services Engine 3.1 is supported until November 3, 2026, its end-of-support date. Active support for Cisco Identity Services Engine 3.1 ends on November 3, 2025; security fixes continue until that end-of-life date. The next Cisco Identity Services Engine version to reach end of life is 3.2, on November 3, 2026. 13 of 18 tracked Cisco Identity Services Engine versions are past end of life; the most recent to reach it, 3.0, did so on July 13, 2024. Every Cisco Identity Services Engine version's release and end-of-support date is on the Cisco Identity Services Engine lifecycle page.

What Cisco fixed, and what the lifecycle says about each train

Cisco's fixed-release table has five rows and a footnote. The three lifecycle columns are from Cisco's per-release ISE end-of-life bulletins as we serve them on the Cisco ISE page. ISE bulletins phase support in three steps: routine software maintenance ends first, after which Cisco publishes only critical security vulnerability and severity-1 fixes; then software maintenance releases end altogether, which is the last day any fix ships; then support ends.

ISE trainFirst fixed releaseRoutine maintenance endsLast fix shipsSupport ends
3.53.5 Patch 4Not yet announcedNot yet announcedNot yet announced
3.43.4 Patch 7Not yet announcedNot yet announcedNot yet announced
3.33.3 Patch 12Not yet announcedNot yet announcedNot yet announced
3.23.2 Patch 11November 3, 2025November 3, 2026November 30, 2027
3.13.1 Patch 12November 3, 2025November 3, 2026November 30, 2027
3.0None; migrateJuly 13, 2023July 13, 2024July 13, 2025
2.7 and olderNot in Cisco's table or CVE recordPast every milestone; see the Cisco ISE page for each bulletin

Read the 3.1 and 3.2 rows carefully, because they are the good news with a clock on it. Both trains share one end-of-life bulletin. Their routine software maintenance ended on November 3, 2025; the bulletin names 3.1 Patch 10 and 3.2 Patch 8 as the last maintenance patches. Patch 12 and Patch 11 arrive under the phase that follows, in which Cisco publishes only critical security vulnerability and severity-1 fixes. That phase is exactly for a CVSS 10.0 flaw under active exploitation, and it worked. It ends on November 3, 2026, the end of software maintenance releases, the last day any fix ships for 3.1 or 3.2. Support itself runs to November 30, 2027, but support after that November day is TAC without patches. The next ISE flaw of this kind, listed after November 3, 2026, will find 3.1 and 3.2 exactly where 3.0 is today.

The 3.0 row is the plain case. Cisco's fixed-release table has no 3.0 line; the footnote reads: "Cisco ISE Software Release 3.0 has reached End of Software Maintenance. Customers are advised to migrate to a supported release that includes the fix." On Cisco's bulletin, 3.0 shipped its last fix on July 13, 2024 and left support on July 13, 2025. There is nothing to apply on that train and no support contract that would produce one.

What we are not saying. We are not listing ISE 3.0 on our Exploited & Unpatchable feed. That feed requires the vendor's own statement that a version is affected, and Cisco's CVE record for CVE-2026-76460 names releases from 3.1.0 to 3.5 as affected; it does not name 3.0 or 2.7. The advisory's footnote tells 3.0 customers to migrate, which is not the same as saying 3.0 is vulnerable, and the feed does not infer what the vendor did not state. If Cisco's record is revised to include 3.0, the entry follows. We are also not saying 3.1 and 3.2 are unsupported: Cisco's bulletin says the opposite until November 2027. We are saying that their fix window is measured in weeks, and that this advisory shows what that window is worth while it is open.
Running Cisco ISE past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers Cisco ISE is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

What to do, by train

3.3, 3.4, 3.5: apply the patch from the table, ahead of September 19 if you are a federal agency and this week regardless. Then do the triage: review the administrator accounts, the API access logs and the policy change history on the deployment before you call it clean. A management-interface bypass leaves its marks in configuration, not in a crash log.

3.1 and 3.2: apply 3.1 Patch 12 or 3.2 Patch 11 now, do the same triage, and put the upgrade to 3.3 or later into the change calendar before November 3, 2026. That is the last day Cisco ships a fix for either train, and the ISE catalog history says a fourth entry is a matter of when. Cisco's bulletin for 3.1 and 3.2 also puts the end of sale on the same day as the end of software maintenance releases, so a new deployment on either train is not an option after it.

3.0 or older: there is nothing to apply. The migration to a fixed release is the fix, and the triage comes first, because a train that shipped its last fix on July 13, 2024 has been exposed to everything listed since, including the two July 2025 entries. Treat the deployment as untrusted until you have looked.

ISE-PIC: CISA's entry names the Passive Identity Connector alongside ISE. Cisco's fixed-release table is the reference for the ISE-PIC build on each train.

Frequently Asked Questions

Which Cisco ISE patches fix CVE-2026-76460?

Cisco's advisory lists one first fixed release per train: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. There is no 3.0 patch; the advisory's footnote says 3.0 has reached End of Software Maintenance and tells customers to migrate to a supported release that includes the fix. There are no workarounds.

What is CISA's deadline for CVE-2026-76460?

CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog on September 16, 2026 with a due date of September 19, 2026 for federal agencies, and marked it as requiring forensic triage under BOD 26-04, meaning agencies must check the appliance for compromise, not only patch it.

Are Cisco ISE 3.1 and 3.2 still supported?

Yes, in a narrowing sense. Cisco's end-of-life bulletin for ISE 3.1 and 3.2 ended routine software maintenance on November 3, 2025; from that day Cisco publishes only critical security vulnerability and severity-1 fixes, which is why Patch 12 and Patch 11 exist. The end of software maintenance releases is November 3, 2026, the last day any fix ships, and the last date of support is November 30, 2027.

What about Cisco ISE 3.0 and older?

ISE 3.0 ended software maintenance releases on July 13, 2024 and support on July 13, 2025, and Cisco's advisory has no 3.0 row: the footnote tells 3.0 customers to migrate. Cisco's own CVE record names releases from 3.1.0 to 3.5 as affected and does not name 3.0 or 2.7, so 3.0 is not on our Exploited and Unpatchable feed; that feed requires the vendor's own affected statement and does not infer one.

Related

© 2026 endoflife.ai · How we verify our dates · API · About