LATEST View all updates

Cisco ISE September 2026 Critical Security Updates: What to Patch

Cisco published multiple Critical ISE advisories with different prerequisites, workarounds and fixed releases.

Cybersecurity administrator comparing multiple Cisco ISE September 2026 vulnerability and patch paths

Signal Brief

  • Cisco's September 2026 ISE batch contains multiple Critical advisories, but authentication, configuration and product prerequisites differ.
  • ISE 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4 are common current fixed destinations across many advisories, but CVE-level exceptions remain.
  • CVE-2026-76460's known active exploitation must remain separate from vulnerabilities for which Cisco reports no known malicious use.
  • ISE-PIC exposure and workaround availability vary by advisory, so administrators should not use one generic affected-versus-fixed row.

Cisco ISE September 2026 critical security updates should not be treated as one uniform vulnerability batch. Cisco published multiple ISE and ISE-PIC advisories on September 16, including Critical flaws, but the authentication requirements, configuration prerequisites, affected products, workarounds and first fixed releases differ by advisory and sometimes by individual CVE.

For many of the Critical September advisories, Cisco’s current fixed-release path converges on ISE 3.3 Patch 12, ISE 3.4 Patch 7 and ISE 3.5 Patch 4. Older 3.1 and 3.2 deployments may have a fixed patch for some CVEs but require migration for others. Administrators therefore need to map each advisory against the exact product, release, patch level and enabled configuration before deciding what to install.

Cisco ISE September 2026 critical security updates: patch matrix

Advisory Key CVEs Max CVSS Authentication or prerequisite ISE-PIC Workaround Exploitation state Patch direction
ISE Hardening Release CVE-2026-20130, 20192, 20194, 20234, 20237, 20287 10.0 Multiple vulnerability classes; Cisco’s advisory must be checked for each CVE Yes None Do not transfer the separate CVE-2026-76460 exploitation state to this entire set 3.1 Patch 12; 3.2 Patch 11; 3.3 Patch 12; 3.4 Patch 7; 3.5 Patch 4, with older releases requiring migration
ISE Multiple Vulnerabilities advisory CVE-2026-76423 through CVE-2026-76428 10.0 Mixed remote attack classes; applicability differs by CVE Mixed None Cisco PSIRT did not report malicious use for this advisory in the reviewed state CVE-specific; 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4 are key current fixed destinations, while some older releases require migration
Authentication Bypass CVE-2026-76460 10.0 Unauthenticated remote attack path ISE None Known active exploitation according to Cisco’s related advisory state Keep this CVE as a separate urgent incident-response and patching job rather than flattening it into the general batch
Remote Code Execution CVE-2026-20176, 20211, 20307 9.9 Valid administrative credentials required ISE None Cisco PSIRT did not report malicious use in the reviewed advisory state Per-CVE fixed releases differ; 3.3 Patch 12 and 3.4 Patch 7 are key destinations, while 3.5 fixes differ by CVE
Authenticated RCE and API vulnerabilities CVE-2026-20282, 20283, 20284 9.1 CVE-2026-20282 is configuration-independent; CVE-2026-20283 depends on the specified IPsec state; CVE-2026-20284 requires SXP to be enabled with an SXP connection No Available only for CVE-2026-20283 Public announcement exists; Cisco said it was not aware of malicious use in the reviewed advisory state 3.3 Patch 12; 3.4 Patch 7; 3.5 Patch 4, with CVE-specific treatment on older releases
Command Injection CVE-2026-20305, 20306 9.1 Valid administrative credentials required Yes None Cisco PSIRT did not report malicious use in the reviewed advisory state CVE-2026-20305 follows the newer patch baseline; CVE-2026-20306 has narrower release and patch-state applicability that must be checked separately
Cisco ISE September 2026 patch matrix showing different authentication, configuration and fixed-release paths
Administrators must keep authentication, configuration, workaround and exploitation states separate across the September ISE advisories.

Do not assume every Cisco ISE Critical flaw is unauthenticated

No. The September advisory set contains materially different attack prerequisites. CVE-2026-76423 is described in Cisco’s six-CVE advisory as an unauthenticated REST API authentication-bypass issue. By contrast, the separate remote-code-execution advisory covering CVE-2026-20176, CVE-2026-20211 and CVE-2026-20307 requires valid administrative credentials.

The command-injection advisory covering CVE-2026-20305 and CVE-2026-20306 also requires valid administrative credentials. Treating every Critical or High-severity entry as an unauthenticated internet-facing exploit would overstate the actual exposure.

Configuration matters for CVE-2026-20282, 20283 and 20284

Cisco’s authenticated RCE and API advisory has three different exposure states. CVE-2026-20282 does not depend on the same special configuration prerequisites as the other two. CVE-2026-20283 depends on the IPsec-related state described by Cisco, while CVE-2026-20284 requires SXP to be enabled with an SXP connection.

This is why TPS is not using a single generic ‘affected’ flag for the September batch. Administrators must check whether the relevant feature or configuration is present before deciding that a CVE applies.

Which September advisory has a workaround?

Cisco lists a workaround for CVE-2026-20283 in the authenticated RCE and API advisory. That workaround does not automatically apply to CVE-2026-20282 or CVE-2026-20284, and it should not be treated as a workaround for the wider September ISE advisory set.

For the other Critical advisories reviewed by TPS, Cisco’s primary remediation is fixed software rather than a batch-wide workaround.

What should ISE 3.3, 3.4 and 3.5 administrators target?

Across many of the Critical September advisories, the current Cisco tables converge on ISE 3.3 Patch 12, ISE 3.4 Patch 7 and ISE 3.5 Patch 4 as important fixed-release destinations.

That does not mean one row can replace Cisco’s individual advisory tables. Some CVEs have different first-fixed levels, and the 3.5 train in particular contains CVE-level differences in the authenticated RCE advisory. Use the common versions as a remediation baseline, then verify every applicable CVE against its own advisory.

What should ISE 3.1 and 3.2 administrators do?

Older trains require more care. Cisco provides 3.1 Patch 12 and 3.2 Patch 11 fixes for some vulnerabilities, while other CVEs in the same September family require migration to a later fixed release.

Cisco’s hardening guidance also recommends moving older maintenance-phase releases to a supported release that contains the full hardening set. Administrators on 3.1 or 3.2 should therefore avoid assuming that installing one final patch resolves every September advisory.

Does every advisory affect ISE-PIC?

No. Product applicability differs. Cisco’s advisory covering CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 states that ISE-PIC is not affected, while other September advisories do include ISE-PIC exposure.

Inventory whether the deployment is Cisco ISE, ISE-PIC or both before using a patch matrix.

Keep CVE-2026-76460 exploitation separate

CVE-2026-76460 is the September ISE authentication-bypass case associated with known active exploitation in Cisco’s current advisory context. That exploitation state must not be copied to unrelated vulnerabilities merely because they were published in the same September batch.

For the other reviewed advisories, Cisco generally states that its Product Security Incident Response Team was not aware of malicious use at the time of the reviewed advisory. One advisory also notes a public announcement without reporting known malicious exploitation.

Why one generic Cisco ISE patch row is unsafe

The September release contains six variables that materially change the remediation decision: exact CVE, product, release and patch level, authentication requirement, configuration prerequisite, workaround availability and exploitation state.

A deployment can therefore be exposed to one CVE but not another in the same advisory family. Likewise, one CVE may be fixed by installing a patch on the current train while another requires migration.

What Cisco ISE administrators should check now

  • Record whether the deployment is ISE, ISE-PIC or both.
  • Record the exact major release and installed patch level.
  • Check every applicable September 16 advisory separately.
  • Confirm whether the CVE requires authentication or administrative credentials.
  • Check configuration prerequisites such as SXP or the relevant IPsec state where Cisco lists them.
  • Do not apply a workaround from one CVE to another unless Cisco explicitly says it applies.
  • Compare the deployment with the first fixed release for each applicable CVE.
  • For older 3.1 and 3.2 deployments, determine whether Cisco requires migration rather than only another patch.
  • Keep CVE-2026-76460’s active-exploitation response separate from non-exploited advisory states.

Bottom line

Cisco’s September 2026 ISE security release is a patch-matrix problem, not a single-vulnerability problem. Many Critical advisories point administrators toward 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4, but exact remediation still depends on the CVE, product, authentication state, enabled configuration and current release.

The safest approach is to inventory the deployment and work through each Cisco advisory individually. Do not infer active exploitation, unauthenticated access, ISE-PIC exposure or workaround availability across the whole batch.

Verification note

TPS reviewed Cisco’s September 16 ISE advance notice, ISE product security advisory list, hardening release and individual PSIRT advisories covering the Critical authentication-bypass, remote-code-execution, API and command-injection vulnerability groups.

Limitations and unresolved facts

Cisco may revise affected-release tables, fixed software, workaround guidance or exploitation status after publication. This article does not replace Cisco’s advisory-specific applicability checks for a production deployment. TPS also did not establish generic search-volume or Google Trends evidence for this query family.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led informational and editorial security guidance based on Cisco PSIRT advisories reviewed for the September 2026 ISE release. Vulnerability applicability, authentication requirements, configuration prerequisites, workarounds and fixed releases differ by advisory and CVE. Verify your exact ISE or ISE-PIC version, configuration and the current Cisco advisory before making production patching or migration decisions.