Cisco ISE, Email Gateway Zero-Days Exploited: Patch Now

Two Cisco zero-days—an ISE authentication bypass and a Secure Email Gateway SQL injection—are under active exploitation and listed in CISA's KEV catalog.

Cisco has confirmed that two critical vulnerabilities are being actively exploited in the wild: CVE-2026-76460, a maximum-severity (CVSS 10.0) authentication-bypass flaw in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), and CVE-2026-76461, a critical (CVSS 9.8) SQL injection flaw in Cisco Secure Email Gateway that can be triggered by a single crafted email. Both bugs let an unauthenticated remote attacker reach root-level command execution, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both to its Known Exploited Vulnerabilities (KEV) catalog with short federal remediation deadlines. Cisco has published fixed software for each and says no workarounds exist, so patching is the only real fix. Administrators running either product should treat this as an emergency change.

Quick facts

  • CVE-2026-76460 — Cisco ISE / ISE-PIC authentication bypass, CVSS 10.0, actively exploited, added to CISA KEV Sept. 16, 2026.
  • CVE-2026-76461 — Cisco Secure Email Gateway SQL injection, CVSS 9.8, actively exploited, added to CISA KEV Sept. 14, 2026.
  • Both flaws allow unauthenticated, remote attackers to reach root on the affected appliance.
  • No workarounds exist for either vulnerability — upgrading to a fixed release is the only remediation.

What happened

Cisco's Product Security Incident Response Team (PSIRT) disclosed two unrelated but similarly severe vulnerabilities in mid-September 2026, both already under attack before or around the time fixes shipped. On September 14, 2026, Cisco published an advisory for CVE-2026-76461 in Secure Email Gateway (AsyncOS software), saying its PSIRT "became aware of active exploitation of this vulnerability" in September 2026. Two days later, on September 16, 2026, Cisco disclosed CVE-2026-76460, a perfect-10 authentication bypass in Identity Services Engine, stating plainly that it is "aware of active exploitation of this vulnerability" as well. CISA independently corroborated both by adding each CVE to its Known Exploited Vulnerabilities catalog on the same day, or within a day, of Cisco's disclosure — a signal CISA reserves for vulnerabilities it has confirmed are being used in real attacks, not just theoretical risk.

The pairing of an identity-and-access-control product (ISE governs network access policy) with an email security gateway (which sits directly in an organization's inbound mail path) gives attackers two very different but equally valuable footholds: one into the network access-control plane, the other into the mail flow of the organization. Both products are commonly deployed at the network edge or as trusted internal infrastructure, which is exactly why unauthenticated, remote, root-level bugs in them draw immediate attacker interest.

CVE-2026-76460: Cisco Identity Services Engine authentication bypass

CVE-2026-76460 is caused by insufficient authentication control on an API endpoint exposed by Cisco ISE and ISE-PIC. According to Cisco's advisory, an unauthenticated, remote attacker can send a specially crafted request to the affected API to bypass authentication entirely and gain unauthorized access to the product's web-based management interface, without needing valid credentials or any user interaction. Cisco's Cisco Security Advisory cisco-sa-ISE-ABP-VNSW7Tn5 rates the flaw CVSS 3.1 base score 10.0, the maximum possible, with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. That vector reflects a network-reachable attack (AV:N) requiring low attack complexity (AC:L), no privileges (PR:N), and no user interaction (UI:N), with a scope change (S:C) and complete loss of confidentiality, integrity and availability once exploited.

CISA's KEV catalog entry lists the flaw under the name "Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability," tracked to CWE-648 (incorrect use of privileged APIs). Because ISE is the policy brain behind 802.1X, TACACS+ and network-access-control decisions across an enterprise, an attacker who bypasses its management interface can potentially read or alter the policies that decide which devices and users are allowed onto the network — a scenario Cisco and CISA both treat as critical infrastructure risk rather than a routine bug.

CVE-2026-76461: Secure Email Gateway SQL injection

CVE-2026-76461 sits in the email-parsing logic of Cisco AsyncOS Software, the operating system that runs on Cisco Secure Email Gateway appliances. Per Cisco's Cisco Security Advisory cisco-sa-esa-inj-2bLVGmhX, the vulnerability is due to "insufficient validation in the email parsing logic," and an unauthenticated remote attacker can exploit it simply by sending a specially crafted email containing malicious SQL statements through an affected device. Successful exploitation lets the attacker execute arbitrary SQL statements against the gateway's database, which in turn can be leveraged into operating-system command execution with root privileges on the underlying appliance — no login, no attachment click, no user action required beyond the gateway processing the inbound message.

Cisco scores CVE-2026-76461 at CVSS 3.1 base score 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. CISA's KEV catalog lists it as the "Cisco Secure Email Gateway SQL Injection Vulnerability," mapped to CWE-89 (SQL injection), and separately flags it as requiring forensic triage under CISA's binding operational directive guidance — a designation CISA applies when a KEV entry may indicate deeper compromise beyond simply patching the hole.

Severity and confirmed exploitation status

Both vulnerabilities meet the same three bars that define a genuine "patch now" alert: vendor-confirmed active exploitation, a critical CVSS score, and inclusion in CISA's KEV catalog. Here is how the two compare side by side:

DetailCVE-2026-76460CVE-2026-76461
Affected productCisco Identity Services Engine (ISE) & ISE-PICCisco Secure Email Gateway (AsyncOS)
Flaw typeAuthentication bypass on an API endpoint (CWE-648)SQL injection in email parsing (CWE-89)
CVSS 3.1 base score10.0 (Critical)9.8 (Critical)
Authentication requiredNoneNone
User interaction requiredNoneNone (triggered by inbound email)
ImpactBypass management interface; potential root accessArbitrary SQL execution leading to root OS command execution
Cisco-confirmed active exploitationYesYes
CISA KEV catalogAdded September 16, 2026Added September 14, 2026
Federal remediation due dateSeptember 19, 2026September 17, 2026
Workaround availableNoneNone

CISA KEV catalog listing and what it means

Inclusion in the CISA Known Exploited Vulnerabilities catalog entry for CVE-2026-76460 and the catalog entry for CVE-2026-76461 is not a routine listing exercise. CISA only adds a CVE to the KEV catalog once it has evidence the flaw is being exploited in real-world attacks, and Binding Operational Directive 26-04 requires U.S. federal civilian executive branch (FCEB) agencies to remediate KEV-listed flaws by the stated due date — September 19, 2026 for the ISE bug and September 17, 2026 for the Secure Email Gateway bug. Both entries carry CISA's standard guidance for private-sector and non-federal organizations: apply the vendor's fix immediately, and if a fix cannot be applied, discontinue use of the affected product until it can be. Both catalog entries for these Cisco flaws are also flagged as requiring forensic triage, underscoring that organizations should look for signs of prior compromise, not just apply the patch and move on.

Each CVE also carries an official record in the National Vulnerability Database entry for CVE-2026-76460 and the NVD entry for CVE-2026-76461, where NIST publishes the CVSS scoring, CWE classification and vendor references for each flaw alongside Cisco's own advisory.

Affected products and versions

For CVE-2026-76460, Cisco's advisory covers Cisco ISE and ISE-PIC across the 3.1 through 3.5 release trains; ISE 3.0 has already reached End of Software Maintenance and is not covered by a patch, meaning organizations still running it need to migrate to a supported release before they can remediate at all. Cisco's fixed releases are:

  • ISE/ISE-PIC 3.1 — fixed in Patch 12
  • ISE/ISE-PIC 3.2 — fixed in Patch 11
  • ISE/ISE-PIC 3.3 — fixed in Patch 12
  • ISE/ISE-PIC 3.4 — fixed in Patch 7
  • ISE/ISE-PIC 3.5 — fixed in Patch 4

For CVE-2026-76461, the advisory covers physical and virtual Cisco Secure Email Gateway appliances running AsyncOS Software versions in the 15.5, 16.0 and 16.5 trains, regardless of configuration. Cisco's fixed releases are:

  • AsyncOS 15.5 and earlier — fixed in 15.5.5-014
  • AsyncOS 16.0 — fixed in 16.0.4-302
  • AsyncOS 16.5 — fixed in 16.5.0-780 (Cisco's recommended migration target)

What administrators should do right now

Because Cisco states there are no workarounds for either vulnerability, the only complete remediation for both is to install the fixed AsyncOS or ISE software listed above. Recommended immediate steps:

  • Inventory first. Identify every Cisco ISE, ISE-PIC and Secure Email Gateway instance (physical and virtual) in the environment, including any that are internet-facing or reachable from lower-trust network segments.
  • Patch on an emergency basis. Upgrade ISE/ISE-PIC to the patch level listed for your release train, and upgrade Secure Email Gateway appliances to the fixed AsyncOS build for your train — Cisco recommends moving to 16.5.0-780 where feasible.
  • Migrate end-of-life software. ISE 3.0 deployments cannot receive a fix for CVE-2026-76460 and must be upgraded to a supported, patched release train.
  • Apply temporary compensating controls where patching is delayed. For ISE, Cisco points to infrastructure access control lists (iACLs) restricting management and control-plane traffic to trusted hosts as an interim risk-reduction step — not a substitute for patching, since no workaround eliminates the underlying flaw.
  • Assume compromise is possible and investigate. Given CISA's forensic-triage guidance on both KEV entries, review ISE administrative access logs and Secure Email Gateway mail-processing logs for anomalous activity predating the patch, particularly on internet-exposed or lightly monitored appliances.
  • Track federal deadlines even if you're not a federal agency. CISA's September 19 (ISE) and September 17 (Secure Email Gateway) due dates apply to FCEB agencies under BOD 26-04, but they're a useful benchmark for how urgently any organization should be moving.

This pattern of unauthenticated, remote, root-level flaws in edge and identity infrastructure has become a recurring theme across vendors this year — see Pandromeda's coverage of the actively exploited Citrix NetScaler flaws and the Check Point vulnerabilities added to the KEV catalog earlier this year, both of which followed a similar disclosure-then-emergency-patch timeline.

Why identity and email infrastructure are high-value targets

ISE and Secure Email Gateway occupy two of the most sensitive positions in enterprise infrastructure. ISE effectively decides who and what is allowed onto the network — compromising it can give an attacker a path to manipulate access policy, potentially opening the door to lateral movement across an entire enterprise. Secure Email Gateway sits inline in the flow of every inbound message, meaning an attacker doesn't need a phished credential or a malicious attachment opened by a victim; a single crafted email reaching the gateway is enough to trigger code execution. That combination — no authentication, no user interaction, and root-level impact — is precisely why both vulnerabilities were fast-tracked into CISA's KEV catalog within days of disclosure and why remediation windows were measured in days rather than weeks. The same access-control-and-messaging-infrastructure targeting pattern echoes recent exploited flaws in other perimeter products, including the F5 BIG-IP APM vulnerability Pandromeda covered earlier this month.

What's next

Expect both advisories to be updated as Cisco and CISA gather more telemetry: Cisco already revised the Secure Email Gateway advisory once (to version 1.1) after initial publication, and KEV entries are periodically updated with additional notes as investigations progress. Organizations that have already patched should still review logs for exploitation attempts predating remediation, since both flaws were exploited before or immediately after public disclosure. Given the severity and the absence of any workaround, security teams should treat unpatched ISE and Secure Email Gateway instances as an active incident-response priority rather than a routine patch-cycle item, and should continue to monitor Cisco's own advisory pages and CISA's KEV catalog for any updates to affected versions, fixed releases, or exploitation indicators.

Frequently asked questions

Are CVE-2026-76460 and CVE-2026-76461 actively being exploited?

Yes. Cisco's own advisories state its Product Security Incident Response Team (PSIRT) is aware of active exploitation of both vulnerabilities, and CISA has independently added both CVEs to its Known Exploited Vulnerabilities (KEV) catalog, a designation reserved for confirmed real-world exploitation.

What is CVE-2026-76460?

CVE-2026-76460 is a critical (CVSS 10.0) authentication-bypass vulnerability in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), caused by insufficient authentication control on an API endpoint. It lets an unauthenticated remote attacker bypass authentication and gain unauthorized access to the management interface.

What is CVE-2026-76461?

CVE-2026-76461 is a critical (CVSS 9.8) SQL injection vulnerability in the email-parsing logic of Cisco AsyncOS Software for Secure Email Gateway. An unauthenticated attacker can send a specially crafted email containing malicious SQL statements to achieve operating-system command execution with root privileges.

Are these CVEs in CISA's Known Exploited Vulnerabilities catalog?

Yes. CISA added CVE-2026-76461 to the KEV catalog on September 14, 2026 (federal remediation due September 17, 2026) and CVE-2026-76460 on September 16, 2026 (federal remediation due September 19, 2026).

Which versions are affected and what should administrators do?

CVE-2026-76460 affects Cisco ISE/ISE-PIC 3.1 through 3.5 (fixed in 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4); ISE 3.0 is end of software maintenance and must be upgraded to a supported release. CVE-2026-76461 affects Secure Email Gateway appliances on AsyncOS 15.5, 16.0 and 16.5 (fixed in 15.5.5-014, 16.0.4-302 and 16.5.0-780). Cisco says there are no workarounds for either flaw, so administrators should apply the fixed software immediately.

Is there a temporary mitigation if I can't patch immediately?

Cisco states no workaround eliminates either vulnerability. For CVE-2026-76460, Cisco points to infrastructure access control lists (iACLs) restricting management-plane traffic as a temporary risk-reduction step, but this does not replace patching. No interim mitigation is offered for CVE-2026-76461.

Sources

More on Cisco ISE →CiscoCisco ISESecure Email GatewayCVE-2026-76460CVE-2026-76461CISA KEV
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all