Lucian Constantin
CSO Senior Writer

Cisco patches max-severity ISE flaw, the second critical zero-day this week

News
Sep 17, 20263 mins

Under active exploitation, the 10.0 Identity Services Engine vulnerability can give attackers root privileges without authentication.

Cisco building exterior with sign
Credit: Ken Wolter / Shutterstock

Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network access control and policy enforcement. This is the second zero-day flaw Cisco has been forced to release emergency patches for this week, after fixing a critical vulnerability in its Secure Email Gateway appliance.

The Cisco ISE flaw, tracked as CVE-2026-76460, has the maximum severity score of 10.0 on the CVSS scale and can be exploited without authentication to gain root-level privileges on the device. The vulnerability is in an API endpoint used for management and can be exploited by sending crafted requests that bypass the normal web-based management interface completely.

The flaw affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC) in all configurations and was fixed in versions 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4, depending on which major software release is being used.

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, indicating that exploitation in the wild has been confirmed.

Mitigation

Users of Cisco ISE and ISE-PIC are advised to check the access.log on their devices and search for suspicious usernames, which could be an indicator of successful compromise. However, because attackers gain root access through this vulnerability, they could delete the logs to hide their tracks, in which case network and firewall logs upstream of the devices should also be checked for suspicious activity such as file uploads and downloads initiated from the devices with unauthorized IP addresses.

“If malicious activity is suspected, it is strongly recommended to re-image the affected nodes and restore from configuration backup if needed,” the company said.

Cisco also advises administrators use infrastructure access control lists (iACLs) to limit who can send management and control traffic to the affected devices.

More critical flaws patched in Cisco ISE

This is not the only vulnerability fixed in Cisco ISE this week. The company did a comprehensive review of the Cisco ISE and ISE-PIC platforms, uncovering and fixing a total of 21 critical vulnerabilities, including remote code execution ones and other API flaws that fall in the same class as CVE-2026-76460. The releases also address three high-severity flaws and 18 medium-severity ones.

Separately the company also patched critical- and medium-severity flaws in Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software. Older vulnerabilities in these products have been exploited by different threat actors this year, particularly CVE-2026-20079 and CVE-2026-20131 affecting the FMC software that were originally patched in March.

Lucian Constantin

Lucian Constantin writes about information security, privacy, and data protection for CSO. Before joining CSO in 2019, Lucian was a freelance writer for VICE Motherboard, Security Boulevard, Forbes, and The New Stack. Earlier in his career, he was an information security correspondent for the IDG News Service and Information security news editor for Softpedia.

Before he became a journalist, Lucian worked as a system and network administrator. He enjoys attending security conferences and delving into interesting research papers. He lives and works in Romania.

You can reach him at lucian_constantin@foundryco.com or @lconstantin on X. For encrypted email, his PGP key's fingerprint is: 7A66 4901 5CDA 844E 8C6D 04D5 2BB4 6332 FC52 6D42

More from this author