Cisco ISE CVE-2026-76460: 3.1 to 3.5 Patched, 3.1 and 3.2 End Nov 3
The management interface is the target, and no login is needed. Cisco's advisory cisco-sa-ISE-ABP-VNSW7Tn5, published on the day CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog, September 16, 2026, describes an API endpoint in Cisco Identity Services Engine and the ISE Passive Identity Connector with, in Cisco's words, "insufficient authentication control on an API endpoint". An unauthenticated, remote attacker who sends a crafted request to it bypasses the web-based management interface and gains unauthorized access to the appliance. CVSS 10.0, the top of the scale. No workarounds. Cisco says it found the flaw during the resolution of a TAC support case, and the advisory states plainly: "The Cisco PSIRT is aware of active exploitation of this vulnerability."
ISE is the box that decides who gets onto the network. It holds the RADIUS and TACACS+ policy, the device certificates, the posture rules and the administrator accounts for the switches and firewalls it talks to. An attacker with unauthorized access to it is not on one server; they are at the front desk with the master key. That is why CISA's entry carries the forensic-triage flag, and why this is the third ISE entry in CISA's catalog: the earlier two, CVE-2025-20281 and CVE-2025-20337, were added on July 28, 2025.
What Cisco fixed, and what the lifecycle says about each train
Cisco's fixed-release table has five rows and a footnote. The three lifecycle columns are from Cisco's per-release ISE end-of-life bulletins as we serve them on the Cisco ISE page. ISE bulletins phase support in three steps: routine software maintenance ends first, after which Cisco publishes only critical security vulnerability and severity-1 fixes; then software maintenance releases end altogether, which is the last day any fix ships; then support ends.
| ISE train | First fixed release | Routine maintenance ends | Last fix ships | Support ends |
|---|---|---|---|---|
| 3.5 | 3.5 Patch 4 | Not yet announced | Not yet announced | Not yet announced |
| 3.4 | 3.4 Patch 7 | Not yet announced | Not yet announced | Not yet announced |
| 3.3 | 3.3 Patch 12 | Not yet announced | Not yet announced | Not yet announced |
| 3.2 | 3.2 Patch 11 | November 3, 2025 | November 3, 2026 | November 30, 2027 |
| 3.1 | 3.1 Patch 12 | November 3, 2025 | November 3, 2026 | November 30, 2027 |
| 3.0 | None; migrate | July 13, 2023 | July 13, 2024 | July 13, 2025 |
| 2.7 and older | Not in Cisco's table or CVE record | Past every milestone; see the Cisco ISE page for each bulletin | ||
Read the 3.1 and 3.2 rows carefully, because they are the good news with a clock on it. Both trains share one end-of-life bulletin. Their routine software maintenance ended on November 3, 2025; the bulletin names 3.1 Patch 10 and 3.2 Patch 8 as the last maintenance patches. Patch 12 and Patch 11 arrive under the phase that follows, in which Cisco publishes only critical security vulnerability and severity-1 fixes. That phase is exactly for a CVSS 10.0 flaw under active exploitation, and it worked. It ends on November 3, 2026, the end of software maintenance releases, the last day any fix ships for 3.1 or 3.2. Support itself runs to November 30, 2027, but support after that November day is TAC without patches. The next ISE flaw of this kind, listed after November 3, 2026, will find 3.1 and 3.2 exactly where 3.0 is today.
The 3.0 row is the plain case. Cisco's fixed-release table has no 3.0 line; the footnote reads: "Cisco ISE Software Release 3.0 has reached End of Software Maintenance. Customers are advised to migrate to a supported release that includes the fix." On Cisco's bulletin, 3.0 shipped its last fix on July 13, 2024 and left support on July 13, 2025. There is nothing to apply on that train and no support contract that would produce one.
What to do, by train
3.3, 3.4, 3.5: apply the patch from the table, ahead of September 19 if you are a federal agency and this week regardless. Then do the triage: review the administrator accounts, the API access logs and the policy change history on the deployment before you call it clean. A management-interface bypass leaves its marks in configuration, not in a crash log.
3.1 and 3.2: apply 3.1 Patch 12 or 3.2 Patch 11 now, do the same triage, and put the upgrade to 3.3 or later into the change calendar before November 3, 2026. That is the last day Cisco ships a fix for either train, and the ISE catalog history says a fourth entry is a matter of when. Cisco's bulletin for 3.1 and 3.2 also puts the end of sale on the same day as the end of software maintenance releases, so a new deployment on either train is not an option after it.
3.0 or older: there is nothing to apply. The migration to a fixed release is the fix, and the triage comes first, because a train that shipped its last fix on July 13, 2024 has been exposed to everything listed since, including the two July 2025 entries. Treat the deployment as untrusted until you have looked.
ISE-PIC: CISA's entry names the Passive Identity Connector alongside ISE. Cisco's fixed-release table is the reference for the ISE-PIC build on each train.
Frequently Asked Questions
Which Cisco ISE patches fix CVE-2026-76460?
Cisco's advisory lists one first fixed release per train: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. There is no 3.0 patch; the advisory's footnote says 3.0 has reached End of Software Maintenance and tells customers to migrate to a supported release that includes the fix. There are no workarounds.
What is CISA's deadline for CVE-2026-76460?
CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog on September 16, 2026 with a due date of September 19, 2026 for federal agencies, and marked it as requiring forensic triage under BOD 26-04, meaning agencies must check the appliance for compromise, not only patch it.
Are Cisco ISE 3.1 and 3.2 still supported?
Yes, in a narrowing sense. Cisco's end-of-life bulletin for ISE 3.1 and 3.2 ended routine software maintenance on November 3, 2025; from that day Cisco publishes only critical security vulnerability and severity-1 fixes, which is why Patch 12 and Patch 11 exist. The end of software maintenance releases is November 3, 2026, the last day any fix ships, and the last date of support is November 30, 2027.
What about Cisco ISE 3.0 and older?
ISE 3.0 ended software maintenance releases on July 13, 2024 and support on July 13, 2025, and Cisco's advisory has no 3.0 row: the footnote tells 3.0 customers to migrate. Cisco's own CVE record names releases from 3.1.0 to 3.5 as affected and does not name 3.0 or 2.7, so 3.0 is not on our Exploited and Unpatchable feed; that feed requires the vendor's own affected statement and does not infer one.
Related
- Cisco ISE — every ISE release Cisco publishes a bulletin for, with its three milestones
- Cisco FMC CVE-2026-20079 — the same month's Cisco listing where two trains got no build at all
- Cisco Secure Email Gateway CVE-2026-76461 — the neighbouring CVE number, listed two days earlier
- EOS Edge Device List — every edge platform we track with a CISA KEV history
- Exploited & Unpatchable — the feed of KEV entries on products past their fix window
- How we verify our dates — the rules every number on this site is held to