Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
Vulnerability threat dossier
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
VTP analyst assessment
CVE-2026-20307 allows a remote attacker with low-privileged administrative credentials to exploit insecure Java deserialization in Cisco ISE's web management interface and execute operating-system commands.
1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Available reports concern CVE-2026-76460, not CVE-2026-20307, and do not support an exploitation claim for this CVE.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Unexpected ISE administrative logins.
VTP deterministic assessment
EPSS is 0.01; this is predictive context, not exploitation evidence.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Material change ledger
Claim provenance
2 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
Event history
BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.
CERT-FR published evidence linked to CVE-2026-20307.
Cisco Product Security Incident Response Team published evidence linked to CVE-2026-20307.
Cisco Product Security Incident Response Team published evidence linked to CVE-2026-20307.
Original publications
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker
De multiples vulnérabilités ont été découvertes dans les produits Cisco. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. Cisco indique que la vulnérabilité CVE-2026-76460 est...
On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery . Cisco Identity Services Engine Title CVE ID SIR Base Score Cisco Identity Services Engine Hardening Release: September 2026 CVE-2026-20130 CVE-2026-20192 CVE-2026-20194 CVE-2026-20234 CVE-2026-20237 CVE-2026-20287 Critical 10.0 Cisco Identity Services Engine Vulnerabilities CVE-2026-76423 CVE-2026-76425 CVE-2026-76426 CVE-2026-76427 CVE-2026-76428 CVE-2026-76424 Critical 10.0 Cisco Identity Services Engine Authentication Bypass Vulnerability CVE-2026-76460 Critical 10.0 Cisco Identity Services Engine Remote Code Execution Vulnerabilities CVE-2026-20211 CVE-2026-20176 CVE-2026-20307 Critical 9.9 Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities CVE-2026-20282 CVE-2026-20283 CVE-2026-20284 Critical 9.1 Cisco Identity Services Engine Command Injection Vulnerabilities CVE-2026-20306 CVE-2026-20305 Critical 9.1 Cisco Identity Services Engine RADIUS Denial of Service Vulnerability CVE-2026-20352 High 8.6 Cisco Identity Services Engine SQL Injection Vulnerabilities CVE-2026-20247 CVE-2026-20300 High 7.5 Cisco Identity Services Engine Cross-Site Scripting Vulnerability</ <br/>Security Impact Rating: Informational
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have valid administrative credentials. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57 This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories . In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026 . <br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20176,CVE-2026-20211,CVE-2026-20307
Technical vulnerability data
Raw observations
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.