Cisco Patches Maximum-Severity ISE Zero-Day Under Active Exploitation
Cisco fixed CVE-2026-76460, a maximum-severity authentication bypass in Identity Services Engine that is being actively exploited, with no available workarounds.
The flaw, tracked as CVE-2026-76460, sits in an application programming interface endpoint and was rated 10 out of 10 on the severity scale. Cisco said it affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of how the devices are configured.
ISE is the vendor's network access control and identity-based policy platform, used by organizations to determine which users and devices may join a corporate network and what resources they may reach once inside. Access to that platform is governed through its web-based management interface.
"A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication," Cisco said in a security advisory. The company attributed the issue to insufficient authentication control on an API endpoint, adding that an attacker could send a crafted request to that endpoint and, on success, gain unauthorized access to the affected device by bypassing the management interface.
In the same advisory, Cisco said its Product Security Incident Response Team is aware of active exploitation and urged customers to upgrade to a fixed software release as soon as possible. According to the company, no workarounds exist for the flaw, making a patch the only solution. The advisory lists the vulnerable versions and their corresponding fixes.
The U.S. Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalog, which gives federal agencies a three-day deadline to patch or stop using ISE entirely. That deadline expires on Sept. 19, 2026.
Cisco published indicators of compromise and advised defenders to search access.log files on every node for suspicious usernames. The company also recommended re-imaging nodes and restoring them from backups in the event of a breach.
The advisory follows a pattern of urgent patching cycles for network infrastructure software, where devices that authenticate users and enforce access policy are often reachable from the internet or from within trusted network segments.
The details were reported by TechRadar, which cited BleepingComputer.