Cisco disclosed two critical authentication bypass vulnerabilities in September 2026: CVE-2026-76460, affecting Identity Services Engine (ISE), and CVE-2026-76504, affecting Catalyst SD-WAN Manager. Cisco has confirmed active exploitation of both and released patches.
MSPs and security teams should identify affected deployments, urgently apply the appropriate updates, and investigate whether attackers already gained access.
CVE-2026-76460: Authentication Bypass in Cisco ISE
Disclosed on September 16 with a CVSS score of 10.0, this vulnerability affects vulnerable releases of Cisco ISE and ISE Passive Identity Connector (ISE-PIC), regardless of configuration. An unauthenticated remote attacker can exploit insufficient authentication controls on an API endpoint to gain unauthorized access. Cisco warns that successful exploitation may lead to command execution with root privileges.
That access also complicates investigation: attackers may remove or hide evidence. Cisco recommends reviewing logs from every ISE node alongside external network and firewall logs. If malicious activity is suspected, Cisco strongly recommends re-imaging affected nodes and restoring configuration backups as needed.
CVE-2026-76504: Admin Access to Cisco SD-WAN Manager
Disclosed on September 30 with a CVSS score of 9.8, this vulnerability affects vulnerable releases of Cisco Catalyst SD-WAN Manager, regardless of configuration. Improper handling of URI encoding allows an unauthenticated remote attacker to send a crafted HTTP request, bypass authentication, and access the API with admin privileges. Cisco became aware of active exploitation during September.
Cisco recommends reviewing serviceproxy-access.log and vmanage-server.log for suspicious requests associated with j_security_check, particularly from unknown or unauthorized IP addresses. Assess these indicators against normal activity to avoid false positives.
What MSPs and Security Teams Should Do
Cisco has released patches for both vulnerabilities. With active exploitation confirmed, defenders should urgently update affected systems to the appropriate fixed release and review available logs for signs of compromise. Cisco also provides temporary access restrictions to reduce exposure while updates are deployed. These mitigations do not replace patching.
Start by checking your infrastructure and customer environments against Cisco’s affected-version and fixed-release tables. Prioritize exposed management interfaces, restrict access to trusted systems, and preserve logs for investigation.
Patching closes the vulnerability but does not remove access or persistence an attacker may already have established. When authentication bypass affects network access and management infrastructure, patch deployment and compromise assessment should move together.