Threat Advisory

A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device (CVE-2026-76424)

HIGH CVSS 7.2 September 16, 2026

What happened

An identified vulnerability has been reported in the REST API of Cisco ISE. This flaw allows an authenticated, remote attacker with administrative privileges to upload or copy arbitrary files on an affected device. The vulnerability stems from insufficient validation during file operations, enabling the attacker to craft file paths that lead to arbitrary file placement and execution of commands with root privileges. Exploiting this vulnerability requires the attacker to have valid administrative credentials, but it does not necessitate any user interaction beyond authentication. The attack can be executed remotely over the network via an exposed service, with no additional action required from users or administrators.

Who is affected

Organisations running Cisco ISE deployments that are accessible over the network are potentially affected. Given the nature of the vulnerability, any affected deployment exposed to external or internal networks with administrative access credentials may be at risk. The severity of the impact underscores the importance of evaluating exposure levels and access controls on the affected services.

Recommended actions

  1. Restrict network access to the affected service. Implement network segmentation and access controls to limit exposure to trusted sources only.
  2. Review and reinforce administrative account security. Ensure that credentials are strong, and consider rotating administrative passwords.
  3. Monitor network traffic for unusual activities that may indicate exploitation attempts, particularly targeting the REST API endpoint of Cisco ISE.
  4. Maintain vigilance for updates or patches from Cisco, as no patch is currently available. Stay informed on the progress of vulnerability mitigation efforts.

Indicators of compromise

At present, specific indicators of compromise have not been provided. Monitoring should focus on suspicious activities related to file uploads or command executions on the affected Cisco ISE devices, particularly around the REST API endpoints and related administrative interfaces.

Affected

Vendors: Cisco

Products: Cisco ISE

Is your organisation exposed?

Argos matches live threat intelligence to your own asset inventory and tells you what actually affects you.

Discover Argos

At a glance

Severityhigh
CVSS7.2
CVECVE-2026-76424
PublishedSeptember 16, 2026
VendorCisco
ProductsCisco ISE

Get in touch

We respond within 1 hour on weekdays
Exeo Logo White Transparent