Skip to content
feed: live
>_0dayNews
cisco
● Breaking

Cisco ISE Zero-Day CVSS 10.0 Under Active Exploitation

CVE-2026-76460, a CVSS 10.0 auth bypass in Cisco ISE and ISE-PIC, is under active exploitation. Patches cover all supported releases; no workarounds exist.

Cisco ISE Zero-Day CVSS 10.0 Under Active Exploitation
Photo: Airman 1st Class Jabes Hernandez Matias / 72nd Air Base Wing / DVIDS / DVIDS · Public Domain (US Government work)
kilobaudDave "Kilobaud" Ferris·Published ·2 min read

Cisco on September 16 confirmed what every ISE administrator needed to know immediately: CVE-2026-76460, a maximum-severity authentication bypass in Identity Services Engine and ISE Passive Identity Connector (ISE-PIC), is under active exploitation in the wild.

The CVSS 3.1 base score is 10.0. There are no workarounds. Patches are available across all supported release branches.

What the flaw does

ISE is Cisco’s network access control platform: it enforces policy on who connects to what, handles 802.1X authentication, and integrates with Active Directory and other identity stores. ISE-PIC is the passive identity gathering component that feeds into that policy engine. Both are affected.

The vulnerability is in how ISE handles a specific API endpoint. The code uses privileged APIs incorrectly, in a way that lets an unauthenticated remote attacker bypass the web-based management interface without credentials. Cisco’s advisory confirms that a successful attacker can achieve root-level command execution on the affected node, and that exploitation enables hiding or deleting forensic indicators afterward. That last point matters for anyone doing incident response on a potentially compromised ISE deployment: what you can see in the logs may not be complete.

Affected versions and patches

Cisco has released patches across all supported branches:

  • ISE/ISE-PIC 3.5: Patch 4
  • ISE/ISE-PIC 3.4: Patch 7
  • ISE/ISE-PIC 3.3: Patch 12
  • ISE/ISE-PIC 3.2: Patch 11
  • ISE/ISE-PIC 3.1: Patch 12

No workarounds exist. Cisco’s guidance for nodes where malicious activity is suspected is re-image rather than attempt cleanup.

CISA’s three-day clock

CISA added CVE-2026-76460 to the Known Exploited Vulnerabilities catalog on September 16, 2026, the same day Cisco published the patch. Federal civilian agencies operating under BOD 26-04 have until September 19 to apply mitigations.

Three days. For a platform as embedded in network architecture as ISE, that is a tight window: getting the right patch, testing against a staging environment, scheduling a maintenance window. The mandate is the mandate regardless.

The broader pattern

This is the third Cisco product in two weeks to arrive at the same intersection: maximum or near-maximum severity, confirmed exploitation, CISA mandate. The FMC CVSS 10.0 authentication bypass landed September 10. The Cisco Secure Email Gateway SQL injection with KEV listing followed September 15.

Each was a different product, a different code path, a different attack surface. What they share is the outcome: unauthenticated remote access with high privilege, exploited before or immediately after the advisory landed. The vulnerability types differ. The exploitation cadence does not.

That is the thing worth tracking. A consistent rate of critical findings in enterprise network infrastructure at this scale matters regardless of whether any two flaws share a root cause. Every network-security team running Cisco infrastructure is by now familiar with the response rhythm. That familiarity does not make the window any longer.

Patch the machines.


CVE-2026-76460 is tracked in the 0dayNews KEV tracker. Related coverage: Cisco FMC CVSS 10 auth bypass, Cisco email gateway KEV listing.

Related CVEs
  • [ CRITICAL ]CVE-2026-76460Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Found this useful? Share it.