Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

A Critical Vulnerability in Cisco’s Identity Services Engine Has Been Actively Exploited

Cisco has issued an emergency patch for a severe vulnerability in its Identity Services Engine (ISE) software, which has already been exploited by attackers. The flaw, tracked as CVE-2026-76460, allows hackers to bypass authentication controls and gain access to the affected device. This is particularly concerning because it’s a zero-day vulnerability, meaning that Cisco was not aware of it until after it had been discovered in the wild.

The vulnerability affects both Cisco ISE and its Passive Identity Connector (ISE-PIC) products, regardless of their configuration. It works by allowing attackers to send specially crafted requests to an API endpoint, which is not properly secured. This allows them to bypass the web-based management interface and gain access to the device, essentially giving them root privileges.

The impact of this vulnerability is significant. If exploited successfully, it would allow hackers to execute commands with root privileges, enabling them to hide or delete indicators of compromise (IoCs). To make matters worse, Cisco has not disclosed any information on who is behind these attacks, leaving organizations wondering if their own systems have been compromised.

To mitigate the risk, Cisco recommends that customers upgrade to a fixed software release. The affected versions are ISE 3.1 Patch 12, ISE 3.2 Patch 11, ISE 3.3 Patch 12, ISE 3.4 Patch 7, and ISE 3.5 Patch 4. In the meantime, organizations can use infrastructure access control lists (iACLs) to restrict traffic to the affected device, preventing remote exploitation.

For those who may have already fallen victim to this vulnerability, Cisco provides guidance on how to detect potential compromises. They recommend reviewing “access.log” for suspicious usernames and checking logs for each node in distributed deployments. If malicious activity is suspected, it’s recommended to re-image the affected nodes and restore from configuration backup if needed.

This vulnerability serves as a reminder of the importance of staying up-to-date with security patches and updates. With so many organizations relying on Cisco products, it’s crucial that they take immediate action to protect themselves against this critical vulnerability. In fact, the US Cybersecurity and Infrastructure Security Agency (CISA) has already added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch within three days.

In conclusion, the active exploitation of this zero-day vulnerability highlights the need for organizations to prioritize cybersecurity and take proactive measures to protect themselves against emerging threats. By staying informed and taking prompt action, we can minimize the impact of such vulnerabilities and ensure our digital assets remain secure.


Source: SecurityWeek — 2026-09-17