Cisco Ships Emergency Patch For CVSS-10 ISE Zero-Day Under Attack

Cisco is warning customers to install emergency patches for CVE-2026-76460, a CVSS 10.0 authentication bypass in ISE that is already being exploited to gain root access.

Cisco Ships Emergency Patch For CVSS-10 ISE Zero-Day Under Attack

Cisco has shipped an emergency patch and public advisory for CVE-2026-76460, a maximum-severity authentication bypass in its Identity Services Engine (ISE) that is being actively exploited. The CVSS 10.0 flaw, disclosed on September 17, 2026, lets a remote unauthenticated attacker send a crafted API request and gain root-level command execution on the appliance.

An API endpoint with no auth

Cisco says the vulnerability stems from "insufficient authentication control on an API endpoint" in ISE's web-based management interface. A successful attack bypasses login entirely, giving intruders the ability to run arbitrary commands as root — and, once inside, "remove evidence of compromise". Both Cisco ISE and the ISE Passive Identity Connector (ISE-PIC) are affected.

The company first learned of the flaw through a support ticket where the abuse pattern was already visible, and CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 16.

Cisco Identity Services Engine emergency zero-day patch

Patches by ISE release train

Cisco's advisory lists fixed builds across the currently supported ISE trains:

  • ISE 3.1 — Patch 12
  • ISE 3.2 — Patch 11
  • ISE 3.3 — Patch 12
  • ISE 3.4 — Patch 7
  • ISE 3.5 — Patch 4

There is no viable workaround, so administrators are being told to update immediately, restrict the management interface to trusted networks, and audit ISE hosts for signs of prior compromise — including logs erased by attackers.

Cisco's second maximum-severity ISE hit this year

The disclosure lands only weeks after another critical RCE in Cisco's Nexus 9000 switching gear, and against a backdrop of AI-assisted attackers moving faster than defenders can patch. Recent reports from GreyNoise and Anthropic highlight how quickly threat actors are wiring LLMs into exploitation pipelines.

Enterprise identity is now high-value real estate

ISE sits at the front door of many enterprise networks, handling 802.1X, TACACS+ and network access control. That makes CVE-2026-76460 particularly valuable — a foothold there is a gateway to VLAN pivoting, credential harvesting and lateral movement. Cisco confirmed the flaw is being weaponised now, so treating this as a same-day patch is the safest posture.

Reporting based on coverage from Cisco, The Hacker News, SecurityWeek and CybersecurityNews.

Category: Cyber Security

Tags: Cybersecurity artificial intelligence Zero-Day CVE agentic AI

Related Articles