DIRAS TAKE
Urgent: treat this as high priority because no login is required and successful attacks grant administrative control; immediately block or restrict access to the REST API and follow any Cisco guidance when published.
What is CVE-2026-76423?
Unauthenticated remote attackers can obtain full administrative control of Cisco Identity Services Engine Software under CVE-2026-76423. The flaw affects releases in the 3.x line identified as 3.1.0 (including p1–p6) and 3.2.0 (including p1–p2). The REST API endpoint does not enforce adequate authorization, so an attacker with network reach to that API port can send a specially crafted HTTP request to read and change ISE configuration and identity records with admin privileges.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Which versions of Cisco Cisco Identity Services Engine Software are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Cisco Identity Services Engine Software 3.x | 3.1.0 | |
| Cisco Identity Services Engine Software 3.x | 3.1.0 p1 | |
| Cisco Identity Services Engine Software 3.x | 3.1.0 p3 | |
| Cisco Identity Services Engine Software 3.x | 3.1.0 p2 | |
| Cisco Identity Services Engine Software 3.x | 3.2.0 | |
| Cisco Identity Services Engine Software 3.x | 3.1.0 p4 | |
| Cisco Identity Services Engine Software 3.x | 3.1.0 p5 | |
| Cisco Identity Services Engine Software 3.x | 3.2.0 p1 | |
| Cisco Identity Services Engine Software 3.x | 3.1.0 p6 | |
| Cisco Identity Services Engine Software 3.x | 3.2.0 p2 |
Is CVE-2026-76423 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-76423
- Block or restrict access to the ISE REST API port to trusted management subnets and VPNs only.
- Remove direct internet exposure of ISE and enforce network-level controls (firewall, ACLs) around management interfaces.
- Enable and review detailed API and admin-change logging to detect suspicious requests and configuration modifications.
- Follow Cisco advisories and apply vendor-provided patches or mitigations as soon as they are released.
Frequently asked questions
Is CVE-2026-76423 being actively exploited?
There are no public reports of exploitation of CVE-2026-76423 as of 2026-09-30.
Which Cisco Identity Services Engine Software versions are affected by CVE-2026-76423?
Affected versions listed are 3.1.0, 3.1.0 p1, p2, p3, p4, p5, p6, 3.2.0, 3.2.0 p1, and 3.2.0 p2.
Is there a patch for CVE-2026-76423?
No patch is available for CVE-2026-76423 as of 2026-09-30.
Does CVE-2026-76423 require authentication?
No; the vulnerability can be exploited without authentication if the attacker can reach the ISE REST API port.
References
- nvd.nist.gov/vuln/detail/CVE-2026-76423
- cve.org/CVERecord?id=CVE-2026-76423
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026