Last Updated On

CCTTII--22002266--00991177
CCrriittiiccaall
AAccttiivvee  EExxppllooiittaattiioonn  CCoonnffiirrmmeedd

Walk In Without a Password. Cisco ISE Is Being Exploited.

Cisco just confirmed that the engine deciding who joins the network can be walked into without a password. CVE-2026-76460 is a CVSS 10.0 API authentication bypass in ISE and ISE PIC, already exploited, with no workaround and a plausible path to root. Patch the listed trains, lock the management plane, and treat internet reachable admin interfaces as an incident rather than a ticket.

The same week leaves Secure Email Gateway on fire. CVE-2026-76461 still lets a single crafted message carry SQL into root command execution on AsyncOS, and consulted sources keep the 17 September 2026 remediation clock in play. Hunt mail_logs and off box egress because root can erase what the appliance itself recorded.

No actor, no hash pack, no victim list. A separate 17 September 2026 reporting stream describes FamousSparrow using SparroWocky against Latin American government organizations. Do not glue that campaign to the Cisco bugs. Inventory, restrict, patch, hunt, reimage if anything looks wrong.

10

CVSS Score

18

IOC Count

7

Source Count

80

Confidence Score

CVEs

CVE-2026-76460, CVE-2026-76461

Actors

Under Attribution for Cisco appliance exploitation, FamousSparrow for SparroWocky

Sectors

Identity and network access control, email security, government, enterprise IT

Regions

Global Cisco product exposure, Latin America for SparroWocky government targeting

Chapter 01 - Executive Overview

Cisco disclosed CVE-2026-76460 on 16 September 2026 at 16:00 GMT. The flaw is an insufficient authentication condition on an API endpoint in Cisco ISE and ISE PIC. An unauthenticated remote attacker can send a crafted request, bypass web management authentication, and obtain unauthorized device access. The vendor is aware of active exploitation and warns that successful exploitation may give root command execution, which can be used to remove or conceal evidence. Consulted sources further report government catalog addition on 16 September 2026 with a 19 September 2026 federal remediation clock.

CVE-2026-76461 remains an overlapping emergency inside this window. The flaw is insufficient input validation in Secure Email Gateway email parsing. An unauthenticated attacker can send a crafted message containing malicious SQL statements and potentially reach arbitrary command execution with root privileges. The vendor rates it 9.8 and states it is actively exploited. Consulted sources associate a 17 September 2026 federal remediation clock. There is no complete workaround for either Cisco defect.

This is an emergency identity and email perimeter case, not a routine vulnerability management item.

[+] Identify now: Every ISE and ISE PIC node including distributed, disaster recovery, lab, and dormant members, plus every physical and virtual Secure Email Gateway appliance.

[+] Constrain now: Limit ISE management and control plane reachability with infrastructure access control lists. Separate Secure Email Gateway mail and management interfaces and reduce direct internet exposure.

[+] Patch now: ISE 3.1 to Patch 12, 3.2 to Patch 11, 3.3 to Patch 12, 3.4 to Patch 7, 3.5 to Patch 4. AsyncOS to at least 15.5.5-014, 16.0.4-302, or 16.5.0-780, with migration to 16.5.0-780 where supported.

[+] Hunt now: Review API gateway access.log on every ISE node for usernames that are not in the approved admin inventory. Review mail_logs for suspicious SQL including the documented COPY.*TO PROGRAM pattern. Correlate both with firewall, proxy, DNS, NetFlow, and NDR telemetry because local appliance evidence may already be unreliable.

[+] Rebuild on suspicion: Isolate, preserve external evidence, reimage affected nodes or virtual appliances, and restore from a known good configuration backup. Do not clean in place on a root capable identity or mail appliance.

Separately, consulted reporting on 17 September 2026 describes FamousSparrow use of the SparroWocky backdoor against government organizations in eight Latin American locations. That activity is not attributed to the Cisco exploits and must not be merged into the appliance incident. No actor, victim organization, exploit request body, or atomic network indicator is published for CVE-2026-76460 or CVE-2026-76461.

Chapter 02 - Threat & Exposure Analysis

The exposed ISE condition exists in an API endpoint because of insufficient authentication control. Consulted vendor evidence states that ISE and ISE PIC are affected regardless of device configuration. A crafted request can bypass the web management interface and yield unauthorized device access. Successful exploitation may provide root command execution. Compromise guidance directs defenders to review access.log across every node for suspicious usernames and to review network and firewall telemetry outside the appliance for unexpected uploads to external addresses or downloads from unapproved addresses.

The exposed Secure Email Gateway condition exists in email parsing. Insufficient validation lets a crafted message carry malicious SQL statements into backend processing. Consulted vendor evidence states that physical and virtual appliances are affected regardless of configuration and that the path can escalate from SQL execution to command execution with root privileges. No login and no administrative interface access are required if the appliance processes the message.

[+] What the Cisco incidents do not establish: Internet exposure of any specific ISE API, the exact endpoint URI, HTTP method, request body, request headers, initial source addresses, malicious account names, payloads, exploit code, persistence, lateral movement, data theft, target sectors, or actor identity.

[+] Evidence reliability: Treat local appliance logs as potentially incomplete once root is plausible. Off box firewall, proxy, NetFlow, DNS, EDR, and NDR telemetry are the more reliable record.

[+] SparroWocky as a separate problem: Consulted reporting describes FamousSparrow use of SparroWocky against government organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. Reported capabilities include command and file execution, in memory Beacon Object File loading, system and domain discovery, drive and session enumeration, file transfer and deletion, screenshot capture every 500 milliseconds with delta regions after the first full image, process creation in another logged in user session, TCP proxying, self deletion, DLL side loading, RC4 decrypted payloads in .dat files, runtime API resolution, call stack spoofing, and thread start concealment.

[+] Do not fuse the problems: No consulted evidence ties SparroWocky operators to CVE-2026-76460 or CVE-2026-76461. Treat actor identity for the Cisco exploits as unresolved collection requirements, not assumed campaign details.

Chapter 03 - Operational Response

[+] ISE inventory: Identify every Cisco ISE and ISE PIC instance, version, role, cluster membership, and management or control plane reachability. Include dormant, disaster recovery, lab, and geographically distributed nodes. ISE 3.0 is end of maintenance and must be migrated.

[+] ISE exposure cut: Apply infrastructure access control lists so only required management and control plane traffic can reach affected devices. Maintain an explicit allowlist. Do not treat access lists as remediation.

[+] ISE patch: Upgrade 3.1 to Patch 12, 3.2 to Patch 11, 3.3 to Patch 12, 3.4 to Patch 7, and 3.5 to Patch 4.

[+] ISE hunt: Review API gateway access.log on each node. Any username outside the approved administrator and automation inventory requires investigation. Preserve logs before rotation. Collect support bundles with debug logs and inspect ./ise/logs/apigateway/access.log..gz.

[+] ISE off box validation: Correlate firewall, proxy, NetFlow, DNS, EDR, NDR, and management plane telemetry for anomalous inbound API access and unexpected ingress or egress from ISE node addresses.

[+] Secure Email Gateway patch: Upgrade AsyncOS to at least 15.5.5-014, 16.0.4-302, or 16.5.0-780. Migrate to 16.5.0-780 where supported. There is no workaround.

[+] Secure Email Gateway hunt: Search mail_logs for suspicious SQL statements including COPY.*TO PROGRAM. Review each cluster member. Correlate with gateway, firewall, proxy, DNS, and egress logs. Restrict direct internet exposure and separate mail and management interfaces. Ship logs to an external collector.

[+] Containment on suspicion: Isolate the affected node under change control. Preserve volatile and external evidence. Engage vendor support and incident response. Reimage and restore from a known good configuration backup. Rebuild suspected virtual email appliances from a trusted image rather than cleaning in place.

[+] Post remediation: Confirm the fixed release on every cluster member. Test that approved systems retain required control plane and mail path connectivity. Rotate administrative, integration, API, certificate, and key material based on findings. Review ISE policy and email flow changes made during the plausible compromise interval.

[+] SparroWocky Windows hunt: Hunt unexpected services named ProcAuditManager. Hunt registry persistence named SnapCart under HKLM and HKCU. Investigate unsigned or anomalous DLL side loading chains involving .dat files. Review memory telemetry for Beacon Object File execution, unusual thread start addresses, runtime API resolution, and code loaded outside normal module paths. Search for screenshot collection, TCP proxy behavior, SOCKS5 use, and unusual outbound connections over ports 443 and 8080.


Time

Event

Evidence / confidence

Unknown, more than one year before 17 September 2026

SparroWocky activity reportedly operated against government organizations in Latin America

Consulted reporting; exact start date insufficient data

2026-09-14, 16:00 GMT

Cisco published the Secure Email Gateway advisory for CVE-2026-76461

Vendor advisory; confirmed

September 2026

Cisco became aware of active exploitation of CVE-2026-76461

Vendor advisory; exact day insufficient data

Unknown, before 2026-09-16 16:00 GMT

CVE-2026-76460 exploitation in at least one environment; defect found during a support case

Vendor advisory; first exploit time insufficient data

2026-09-16, 16:00 GMT (21:30 IST)

Cisco published the ISE advisory for CVE-2026-76460 and stated awareness of active exploitation

Vendor advisory; confirmed

2026-09-16

Consulted sources report government catalog addition of CVE-2026-76460 with a 19 September 2026 federal clock

Consulted catalog reporting; direct page not retrieved in every pass

2026-09-16 to 2026-09-17

Independent publications repeat ISE and Secure Email Gateway exploitation, the CVSS 10.0 rating, and the dummyuser hunt example

Corroboration only

2026-09-17

Consulted reporting surfaces FamousSparrow use of SparroWocky against Latin American government organizations

Consulted reporting; primary paper not retrieved in every pass

2026-09-17, 21:03 IST

This assessment prepared

Analyst assessment

2026-09-17

Reported federal remediation clock for CVE-2026-76461

Consulted catalog reporting

2026-09-19

Reported federal remediation clock for CVE-2026-76460

Consulted catalog reporting

Chapter 04 - Detection Intelligence

[+] CVE-2026-76460 attack surface: API endpoint on Cisco ISE and Cisco ISE PIC, regardless of device configuration.

[+] CVE-2026-76460 root cause: Insufficient authentication control, CWE-648 incorrect use of privileged APIs.

[+] CVE-2026-76460 exploit condition: Unauthenticated remote crafted request that bypasses the web management interface.

[+] CVE-2026-76460 impact: Unauthorized device access. Vendor warning that attackers may obtain root command execution and then remove or hide evidence. Scope Changed in the 10.0 vector reflects ISE’s role as an identity and policy broker for wired, wireless, and VPN access, not an isolated host.

[+] CVE-2026-76460 fixed releases: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4. Release 3.0 has no listed fix and must be migrated.

[+] CVE-2026-76460 workaround: None. Infrastructure access control lists are a temporary reachability reduction only.

[+] CVE-2026-76460 not established: Endpoint URI, HTTP method, request body, request headers, whether the bypass sits on API gateway routing versus an application handler, malicious username values, source infrastructure, payload, exploit code, persistence, or lateral movement. Do not invent those details. Public proof of concept is not evidenced in consulted material.

[+] CVE-2026-76461 attack surface: Email parsing on physical and virtual Cisco Secure Email Gateway appliances running AsyncOS, regardless of configuration.

[+] CVE-2026-76461 root cause: Insufficient input validation when processing message content, CWE-89.

[+] CVE-2026-76461 exploit condition: Unauthenticated delivery of a crafted email containing malicious SQL statements.

[+] CVE-2026-76461 impact: Arbitrary SQL execution followed by command execution with root privileges. Ability to alter mail flow, add backdoor accounts, disable logging, and intercept or alter mail.

[+] CVE-2026-76461 fixed releases: 15.5.5-014, 16.0.4-302, 16.5.0-780.

[+] CVE-2026-76461 workaround: None.

[+] SparroWocky execution chain: Consulted reporting describes DLL side loading, RC4 encoded payloads stored in .dat files and mapped in memory, persistence through a Windows service or registry key, and anti analysis designed to hide in memory execution and thread origins.

[+] YARA applicability for the Cisco CVEs: No safe YARA rule is provided. The evidence identifies an API authentication bypass and an email parsing SQL flaw, not a malware file, script, binary, or static byte sequence. Writing YARA for those events would create false confidence.

IOC class

Value

Status / handling

IP address

None published

Insufficient data. Do not block based on this report.

Domain / URL

None published

Insufficient data.

File hash / filename

None published for Cisco exploits. SparroWocky .dat payloads referenced without hashes

Insufficient data.

Malicious username

dummyuser

Vendor search placeholder, not an observed campaign indicator.

ISE log location

ise-kong/access.log and ./ise/logs/apigateway/access.log..gz

Evidence source for hunting, not an IOC.

Secure Email Gateway log location

mail_logs

Evidence source for hunting, not an IOC.

SQL hunt pattern

COPY.*TO PROGRAM

Documented detection example, not an exclusive indicator.

SparroWocky service

ProcAuditManager

Reported behavior, not independently hashed.

SparroWocky registry

SnapCart under HKLM or HKCU

Reported behavior, not independently hashed.

SparroWocky C2

At least 18 addresses reportedly observed

Individual values unavailable. Do not operationalize.

[+] Source grounded ISE CLI hunt: Cisco provided example for an appliance search. The username is a placeholder and must be replaced with locally determined suspect values.

show logging application ise-kong/access.log | include <suspect_username>

[+] Historical ISE logs: Collect a support bundle with debug logs, then inspect files under:

./ise/logs/apigateway/access.log.<date>

[+] SIEM field logic for ISE API anomaly: Implementation neutral pseudocode. Field names are placeholders and must be mapped to the local Cisco ISE parser before deployment.


[+] SIEM field logic for Secure Email Gateway:


[+] SIEM field logic for SparroWocky persistence names:

IF os = "Windows"
AND (
    service.name = "ProcAuditManager"
    OR registry.key CONTAINS "\\

[+] SIGMA style pseudocode for ISE API access:

title: Cisco ISE API Access Anomaly Requiring CVE-2026-76460 Review
id: 8fae1e3a-6d8b-4b45-9dfe-cc7df4f7a2f0
status: experimental
description: >
  Hunt logic for Cisco ISE and ISE PIC API gateway access logs.
  Flags access requiring review after CVE-2026-76460 exploitation confirmation.
  Validate normalized field mappings and approved account or network allowlists locally.
logsource:
  product: cisco
  service: ise_api_gateway
  category: webserver
fields:
  - node_id
  - src_ip
  - username
  - request_path
  - auth_result
  - raw_message
detection:
  selection_api:
    event_category|contains:
      - api_access
      - web_management
      - authentication
  suspicious_username_missing:
    username: null
  suspicious_source_network:
    src_ip|not_cidr:
      - <approved_ise_management_cidr_1>
      - <approved_ise_management_cidr_2>
  filter_approved_automation:
    username|contains:
      - <approved_automation_account_1>
      - <approved_automation_account_2>

[+] SIGMA style pseudocode for unexpected ISE egress:

title: Unexpected External Network Transfer From Cisco ISE Node
id: 7fc1bb8f-d6db-427f-bb2f-074a2e10a7cd
status: experimental
description: >
  Review external network and firewall logs because successful
  CVE-2026-76460 compromise may allow root access and local evidence removal.
logsource:
  category: network_connection
detection:
  selection_ise_source:
    src_ip|cidr:
      - <ise_node_ip_or_subnet>
  filter_approved_destinations:
    dst_ip|cidr:
      - <approved_updates_backups_monitoring_destinations>

[+] SIGMA style pseudocode for Secure Email Gateway SQL pattern:

title: Cisco Secure Email Gateway SQL to Program Exploitation
id: esa-cve-2026-76461-copy-to-program
status: experimental
logsource:
  product: cisco_secure_email_gateway
  service: mail_logs
detection:
  selection:
    message_content|re: "(?i)COPY\\s+.*\\s+TO\\

[+] SIGMA style pseudocode for SparroWocky persistence names:

title: Possible SparroWocky Persistence Names
id: sparrowocky-procauditmanager-snapcart
status: experimental
logsource:
  product: windows
  category:
    - service_installation
    - registry_set
detection:
  service_selection:
    service_name: "ProcAuditManager"
  registry_selection:
    registry_path|contains:
      - "\\

[+] Validation requirements: Consulted advisories do not publish a URI, confirmed username, source address, or complete log schema. Do not convert this pseudocode into blocking automation without parser validation, baselining, a managed allowlist, and testing on a non production event set. Alerting only on the literal string dummyuser will miss real operators.

Framework item

Status

Basis

ATT&CK T1190 Exploit Public Facing Application

Analytic inference; conditional

Remote crafted request to an ISE API or crafted mail to Secure Email Gateway. Public exposure of the ISE API is not established by the advisory.

ATT&CK T1133 External Remote Services

Analytic inference; conditional

Abuse of ISE management or API services that should have been limited to an administrative plane.

ATT&CK T1059 Command and Scripting Interpreter

Analytic inference

Vendor warning of root command execution. Mechanism not described.

ATT&CK T1068 Exploitation for Privilege Escalation

Analytic inference

Unauthenticated access to root impact. Transition method not described.

ATT&CK T1070 Indicator Removal

Analytic inference

Vendor warning that root can remove or hide local evidence.

Initial Access

Analytic inference; conditional

Relevant only if the vulnerable API or mail path is reachable.

Execution / Privilege Escalation

Not confirmed as a source mapping

Consequence described, method not described.

SparroWocky behaviors

Consulted reporting only

DLL side loading, in memory execution, service or registry persistence, discovery, file transfer, screen capture, proxying, defense evasion.

D3FEND control mapping

Inferred, not source mapped

Patching, infrastructure access control lists, centralized off box logging, credential and certificate rotation, trusted rebuild from known good backup.

Chapter 05 - Governance, Risk & Compliance

[+] Accountable executive: Assign a named service owner for every ISE, ISE PIC, and Secure Email Gateway cluster and require written attestation of exposure status, patch status, and evidence review completion.

[+] Emergency change decision: Authorize an emergency patch window. The vendor states there is no workaround for either Cisco defect. Access lists reduce reachability but do not remediate the defect.

[+] Evidence retention: Preserve pre remediation API access logs, mail_logs, firewall, proxy, NetFlow, DNS, NDR, configuration backup, and change management evidence. Local appliance evidence may be incomplete if root access was obtained.

[+] Risk acceptance: Any exception must document affected node, compensating access list, management plane allowlist, expiry date, business owner, and revalidation cadence. Do not approve an open ended exception.

[+] Assurance: Verify fixed releases on all distributed nodes, including passive, disaster recovery, administrative, and virtual appliances. Review node to node consistency and configuration restoration provenance.

[+] Communications: Inform identity, network, SOC, infrastructure, email, and incident response teams. Avoid asserting an actor, a confirmed breach, or government catalog inclusion unless independently verified.

[+] Regulatory clock: Consulted sources describe Binding Operational Directive style deadlines of 17 September 2026 for CVE-2026-76461 and 19 September 2026 for CVE-2026-76460. Non federal operators should use the same clocks for risk parity. Do not make breach notification decisions from the vulnerability alone. Notification thresholds require evidence of affected data, systems, and jurisdiction specific obligations.

[+] Shared services: If ISE or Secure Email Gateway is provided as a shared or managed service, notify tenants that access policy integrity or mail path integrity is in scope.

[+] SparroWocky governance: For Latin American government environments, assess exposure to FamousSparrow related activity without assuming that every SparroWocky like artifact is attributable to that group and without attributing Cisco appliance exploitation to that group.

Chapter 06 - Adversary Emulation

Purpose: Validate detection and response controls without attempting to exploit CVE-2026-76460 or CVE-2026-76461 and without reproducing a crafted bypass request or a malicious SQL message.

Exercise

Safe method

Expected telemetry / outcome

Success criteria

Management plane exposure validation

From an approved test host, verify only allowlisted networks can reach approved ISE management and control services. Do not send malformed or bypass requests.

Firewall allow or deny logs, change ticket, asset inventory confirmation.

Unapproved sources are denied and alerts retain source, destination, rule, and node identity.

API log collection test

Generate a normal, authorized API or web management event using a disposable approved test account in a maintenance window.

API gateway access.log is collected from each node and appears in the SIEM with node, source, username, request context, and outcome.

SOC can retrieve the raw event and correlate it to external network logs.

External transfer analytic test

Generate a small authorized connection from a test ISE adjacent host or approved controlled test path to a pre approved test destination that is temporarily removed from the detection allowlist. Do not alter production ISE configuration.

Firewall, proxy, or NetFlow alert from the unexpected external transfer analytic.

Alert includes device identity, destination, volume, time, and analyst pivot links.

Secure Email Gateway log test

Submit a harmless message containing a non executing marker that resembles the documented SQL detection pattern into a controlled test environment only.

mail_logs, firewall logs, egress telemetry, and SIEM correlation remain available after the test and after upgrades.

SOC can retrieve sender, source address, message identifier, and parser outcome.

SparroWocky detection lab test

Create benign, clearly marked service and registry names in a Windows lab to validate detection logic. Do not deploy or modify SparroWocky.

Service creation and registry set alerts fire with host, user, and parent process.

Rule matches the marked test objects and does not depend on unpublished hashes.

Reimage / restore tabletop

Walk through isolation, evidence preservation, vendor support engagement, reimage, configuration restore, patch verification, and credential review.

Incident ticket, RACI, recovery runbook gaps.

Team can name owner, evidence locations, backup validation method, and recovery time objective.

[+] Do not emulate: Authentication bypass requests, unauthenticated API access, root command execution, destructive configuration changes, exploit payloads, or payload transfer to a production ISE, ISE PIC, or Secure Email Gateway node.

Intelligence Confidence80%

Factor

Score contribution

Reasoning

Vendor product facts

High

Consulted Cisco advisories establish affected products, CVE identifiers, CVSS values, mechanisms at the described level, fixed releases, absence of a complete workaround, and active exploitation.

Independent corroboration

Modest addition

Distinct 17 September 2026 publications repeat ISE and Secure Email Gateway exploitation awareness and the dummyuser hunt example without independently proving unpublished request details.

Government catalog status

Capped

Consulted sources report catalog addition and federal clocks, but the catalog page was not directly retrieved in every collection pass and is not the evidential basis for exploitation.

Attribution and victims

Deduction

No actor, campaign, malware family, or named victim is published for the Cisco exploits.

Atomic indicators

Deduction

No IP address, domain, URL, hash, or exploit sample is published for the Cisco exploits.

Exploit internals

Deduction

URI, method, request body, and execution mechanism remain unpublished.

SparroWocky

Separate 58/100

Behavior, regions, and FamousSparrow linkage appear in consulted reporting attributed to ESET, but the primary paper and concrete command and control list were not retrieved.

Combined Cisco record

80/100

High confidence on what to patch and how to hunt. Low confidence on who exploited the Cisco flaws and where.