Executive Summary
Cisco disclosed CVE-2026-76460, a maximum-severity zero-day vulnerability in Cisco Identity Services Engine (ISE) that was actively exploited before disclosure in December 2026. The vulnerability allows remote attackers to bypass authentication and gain full administrative control of ISE devices through an API flaw. Compromised ISE systems enable attackers to modify network access policies, extract stored credentials, delete audit logs, and move laterally across all network segments controlled by the device. This represents Cisco's second actively exploited zero-day disclosure within two days, highlighting an escalation in targeted attacks against critical network infrastructure.
This incident underscores the growing sophistication of attacks targeting network access control systems and the critical importance of zero-trust architecture as traditional perimeter-based security models continue to fail against advanced persistent threats.
Why This Matters Now
Network access control systems like Cisco ISE are increasingly targeted as they represent single points of failure that can grant attackers enterprise-wide access. With back-to-back zero-day exploits, organizations must immediately reassess their network segmentation strategies.
Attack Path Analysis
Attackers exploited CVE-2026-76460, a critical zero-day vulnerability in Cisco Identity Services Engine (ISE) API that allows authentication bypass to gain root access. With full control over ISE devices that enforce network access policies, attackers modified policies, extracted stored credentials, deleted logs, and moved laterally into every network segment controlled by ISE. This enabled comprehensive network compromise, credential harvesting, and potential data exfiltration across the entire environment.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-76460 zero-day vulnerability in Cisco ISE API to bypass authentication and gain root access to network access control infrastructure
Related CVEs
CVE-2024-20481
CVSS 5.8A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) allows an unauthenticated, remote attacker to bypass authentication and gain administrative access to the affected device.
Affected Products:
Cisco Identity Services Engine (ISE) – < 3.2P7, < 3.3P3
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Impair Defenses: Disable or Modify Tools
Indicator Removal: Clear Windows Event Logs
Remote Services
Abuse Elevation Control Mechanism
Unsecured Credentials: Credentials In Files
Domain Policy Modification: Group Policy Modification
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
CISA ZTMM 2.0 – Authentication and Authorization
Control ID: ZT.A-3
DORA – ICT Risk Management Framework
Control ID: Article 21
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical exposure to Cisco ISE zero-day exploitation enabling authentication bypass, network policy manipulation, credential extraction, and lateral movement across managed IT infrastructures.
Financial Services
High-severity risk from ISE vulnerabilities allowing attackers to bypass network access controls, compromise stored credentials, and violate PCI DSS compliance requirements.
Health Care / Life Sciences
Severe threat to patient data protection as ISE compromise enables policy modification, log deletion, and HIPAA compliance violations through network segmentation bypass.
Government Administration
Critical national security implications from zero-day exploitation allowing full device control, network policy manipulation, and potential access to classified government network segments.
Sources
- Cisco alerts customers to second actively exploited zero-day in as many dayshttps://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/Verified
- Cisco Identity Services Engine Authentication Bypass Vulnerabilityhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-bmjQxKDVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- CVE-2024-20481 Detail - NVDhttps://nvd.nist.gov/vuln/detail/CVE-2024-20481Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain the blast radius of this ISE compromise by limiting lateral movement paths and reducing network-wide exposure. While the initial zero-day exploitation might still occur, segmentation controls could significantly reduce the scope of compromise across network segments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While the zero-day exploitation may still succeed against the ISE API, cloud native security fabric could limit the attacker's ability to pivot from compromised ISE systems to cloud workloads and services through network isolation boundaries.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely limit the scope of privilege escalation by constraining administrative access to isolated network segments, reducing the attacker's ability to leverage ISE administrative privileges across all connected systems.
Control: East-West Traffic Security
Mitigation: East-west traffic security would likely constrain lateral movement between network segments by enforcing granular access controls that don't rely solely on ISE policy decisions, reducing the attacker's ability to traverse the entire network environment.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control would likely detect and constrain unauthorized command and control traffic patterns across network segments, reducing the attacker's ability to maintain persistent communication channels through modified ISE policies.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely constrain data exfiltration by enforcing outbound traffic policies that operate independently of ISE configurations, reducing the attacker's ability to extract large volumes of sensitive data from compromised network segments.
While ISE infrastructure may remain compromised and logs deleted, the overall organizational impact would likely be reduced through maintained segmentation boundaries and preserved visibility in cloud environments not dependent on ISE controls.
Impact at a Glance
Affected Business Functions
- Network Access Control
- Identity Management
- Security Policy Enforcement
- Network Segmentation
Estimated downtime: 3 days
Estimated loss: N/A
Potential exposure of stored network credentials, authentication policies, network access logs, and user identity information managed by ISE systems. Attackers could extract sensitive authentication data and modify access control policies.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement even when network access control systems are compromised, using identity-based policies and microsegmentation
- • Deploy Multicloud Visibility & Control to detect anomalous interactions and suspicious automation that could indicate compromised infrastructure components
- • Establish Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and detect attempts to extract credentials or sensitive configurations
- • Enable Threat Detection & Anomaly Response capabilities to identify baseline deviations and detect covert activities that bypass traditional network controls
- • Implement Inline IPS capabilities to detect and block known exploit patterns targeting critical infrastructure components like network access control systems



