Cisco's Perfect-10 ISE Zero-Day Under Active Attack

Cisco rushes patches for CVE-2026-76460, a max-severity ISE auth bypass actively exploited for unauthenticated root access.

Read as article

Cisco's Perfect-10 ISE Zero-Day Under Active Attack

By @sharedot · · 8 pages

Cisco rushes patches for CVE-2026-76460, a max-severity ISE auth bypass actively exploited for unauthenticated root access.

A perfect 10 that attackers are already using

Cisco disclosed CVE-2026-76460 on Wednesday, a critical authentication bypass in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) carrying the maximum CVSS score of 10.0. According to The Register, the flaw stems from insufficient authentication controls on an API endpoint, letting an unauthenticated remote attacker send a crafted request to bypass the web-based management interface and gain command execution with root privileges. No credentials or user interaction are required, and Cisco says vulnerable versions are affected regardless of configuration. Cisco's PSIRT confirmed it is aware of active exploitation and urged customers to install fixes immediately.

The second emergency patch in days

This is the second zero-day Cisco has been forced to patch urgently this week. CISA added the ISE vulnerability to its Known Exploited Vulnerabilities catalog, and TechRadar reports federal agencies were given a three-day deadline — September 19, 2026 — to patch or stop using ISE entirely.

A sprawling ISE patch release

The zero-day was not an isolated find. According to CSO Online, a comprehensive review of Cisco ISE and ISE-PIC uncovered and fixed 21 critical vulnerabilities in total, including remote code execution flaws and other API weaknesses in the same class as CVE-2026-76460, alongside three high-severity and 18 medium-severity issues. The Register reports two other Cisco advisories published Wednesday also carried maximum CVSS scores of 10.0, with a separate trio of remote code execution flaws scoring as high as 9.9. Cisco discovered the exploited flaw while resolving a Technical Assistance Center support case, but has not said who is exploiting it or how long attacks have been underway.

No workaround — only temporary iACLs

Cisco says no workaround exists for CVE-2026-76460, making patching the only real fix. Patches are available in ISE and ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. ISE 3.0 has reached end of software maintenance, so customers running it must migrate to a supported release. As a temporary stopgap, Cisco recommends infrastructure access control lists to restrict management and control-plane traffic reaching affected systems, allowing only essential and trusted systems to reach ISE management interfaces — a measure Cisco stressed does not remove the underlying vulnerability.

Hunting for traces of a root-level breach

Because attackers gain root access, Cisco warned they could remove or conceal forensic traces, complicating breach assessment. Administrators are advised to review access logs for suspicious usernames on every node in a distributed deployment, and to check network and firewall logs held outside the device for unexpected uploads or downloads. CyberSecurityNews reports Cisco shared an example command for reviewing suspicious login events and suggests collecting support bundles with debug logs enabled for API gateway logs. If exploitation is suspected, Cisco strongly recommends reimaging affected nodes and restoring configurations from a known-good backup.

Why the stakes are so high

ISE is Cisco's network access control platform, deciding who and what is allowed onto an enterprise network and what they can reach inside it. CyberSecurityNews notes a successful compromise gives attackers a high-value entry point into identity and network-management environments, enabling persistence, credential theft, or lateral movement from a fully controlled node. Separately from the Cisco crisis, the same week saw Google patch CVE-2026-58704, a zero-day in the Pixel cellular modem exploited in limited, targeted attacks, added to CISA's KEV catalog on September 16 with a September 19 federal patch deadline — a reminder that this patch cycle is unusually intense across the board.

Sources

  1. theregister.com › Cisco drops another exploited zero-day, this time a perfect 10
  2. csoonline.com › Cisco patches max-severity ISE flaw, the second critical zero-day this week
  3. techradar.com › Cisco hit by max severity zero-day exploit targeting Identity Services Engine
  4. cybersecuritynews.com › Cisco Warns of Critical ISE 0-Day Vulnerability Exploited in Attacks
  5. socprime.com › CVE-2026-58704: Google Pixel Modem Zero-Day

More on Cybersecurity

Cisco's Perfect-10 ISE Zero-Day Under Active Attack · ShareDot