Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has issued a critical security warning about a maximum-severity vulnerability in its Identity Services Engine (ISE) product that’s being actively exploited by attackers. This flaw, tracked as CVE-2026-76460, allows remote hackers to bypass authentication and gain unauthorized access to network resources.

The vulnerability affects the API of Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), which is used to manage endpoints, users, and device access to network resources. Essentially, this means that attackers can send a specially crafted request to an affected API endpoint, allowing them to bypass authentication controls and gain unauthorized access.

“This vulnerability is due to insufficient authentication control on an API endpoint,” Cisco explained in its advisory. “An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint.” A successful exploit would grant the attacker command execution with root privileges, essentially giving them complete control over the affected device.

The issue has been flagged as actively exploited by Cisco’s Product Security Incident Response Team (PSIRT), and the company is urging customers to upgrade to a fixed software release immediately. Unfortunately, there are no workarounds available to mitigate this vulnerability, making upgrading the only effective course of action to protect networks from ongoing attacks.

Cisco ISE or ISE-PIC users can find the first fixed releases listed in the advisory. It’s essential that administrators apply these updates as soon as possible to prevent further exploitation. Additionally, security teams should monitor access.log files on every node for suspicious usernames and look out for indicators of compromise such as downloads and uploads from external or malicious IP addresses.

This is not an isolated incident – Cisco has patched several high-severity vulnerabilities in its products over the past year, including a maximum-severity authentication bypass flaw that was exploited in July 2025. In fact, the Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) Catalog, requiring federal agencies to patch their systems within three days.

In light of this critical vulnerability, it’s crucial for organizations using Cisco ISE or ISE-PIC to take immediate action. We recommend that administrators:

* Immediately apply the security updates listed in the advisory

* Monitor access.log files and firewall logs for suspicious activity

* Re-image affected nodes and restore them from backups if malicious activity is suspected

By taking these steps, you can help protect your network resources from ongoing attacks and prevent further exploitation of this critical vulnerability.


Source: Bleeping Computer — 2026-09-17