The System That Decides Who Gets on Your Network Is Under Active Attack — Cisco ISE Zero-Day Hits CVSS 10.0, and CISA’s Deadline Is Tomorrow

🚨 CRITICAL VULNERABILITY ALERT — Network Access Control / Identity Infrastructure: Cisco has patched a CVSS 10.0 authentication bypass in Identity Services Engine (ISE) that attackers are already exploiting. CISA gave federal agencies three days to fix it. That deadline is tomorrow, Sept 19.

Executive Cyber Threat Intelligence Briefing — September 18, 2026 | DataWater Security Intelligence

The System That Decides Who Gets on Your Network Is Under Active Attack

Cisco ISE is the policy engine behind network access control. It decides which users and devices are trusted. On Wednesday, Cisco disclosed CVE-2026-76460, a flaw in an ISE API endpoint that lets an unauthenticated, remote attacker bypass authentication by sending a crafted request. It affects both ISE and ISE-PIC, regardless of how the device is configured.

New McAfee Banner
Keeper Confetti Image

Cisco’s product security team says it is aware of active exploitation. It has not said who is behind the attacks, how long they have run, or what intruders did once inside.

If an attacker owns the system that grants network access, every other access control you have is now their tool.

Why this one is worse than the CVSS score suggests

Cisco warns that successful exploitation can lead to root command execution. With root, an attacker can hide or delete indicators of compromise. The appliance’s own logs may no longer be trustworthy. That changes how you investigate, not just how you patch.

What We Know

Item Detail
CVE CVE-2026-76460, CVSS 10.0
Product Cisco ISE and ISE-PIC (all configurations)
Attack Unauthenticated remote authentication bypass via a crafted API request
Status Exploited in the wild; Cisco disclosed Sept 16
CISA Added to KEV; federal deadline Sept 19 (three days, under BOD 26-04)
Workaround None. Infrastructure ACLs restricting traffic to the device block remote exploitation until you upgrade
Fixed releases 3.5 Patch 4 · 3.4 Patch 7 · 3.3 Patch 12 · 3.2 Patch 11 · 3.1 Patch 12
End of life ISE 3.0 no longer receives fixes; migrate to a supported release

The same advisory batch included a second maximum-severity authentication bypass (CVE-2026-76423) and several more critical ISE flaws. Those were not flagged as exploited when reported, so patch them in the same window.

The Pattern: Cisco’s Management Plane Is Having a Week

This is the third actively exploited Cisco management-plane story in about a week:

  • Secure Email Gateway: a 9.8-rated flaw (CVE-2026-76461) under active exploitation that can lead to root access.
  • Secure Firewall Management Center: three threat clusters, including a Qilin ransomware operation, exploiting CVE-2026-20079. See our earlier briefing on the two perfect-10 flaws.
  • Identity Services Engine: today’s zero-day.

There is a precedent. In July 2025, attackers exploited another maximum-severity ISE zero-day to plant a web shell disguised as a legitimate ISE component. Attackers know this product and know what it can reach.

The hidden enterprise risk

Security teams patch firewalls first. Identity and access appliances often sit lower on the list, even though they hold trust decisions, device inventories and credentials-adjacent data. Rank your management planes by what an attacker gains, not by how loud the vendor is.

What Security Leaders Should Do Now

  1. Inventory every ISE and ISE-PIC node. Include lab, DR and forgotten deployments.
  2. Restrict access today. Apply infrastructure ACLs so only required management and control-plane traffic reaches the appliance. Do not wait for a maintenance window.
  3. Patch to the fixed release for your branch. Plan a migration for ISE 3.0.
  4. Hunt for compromise, not just patch. Review access.log on every node for unusual usernames. Check logs from all nodes in distributed deployments.
  5. Cross-check outside the appliance. Look at network and firewall logs for unexpected uploads or downloads to and from ISE. Do not rely on on-box logs alone.
  6. If anything looks suspicious, follow Cisco’s guidance to re-image the affected system, then rotate credentials and secrets the appliance could reach.
  7. Brief your board in one line: “A maximum-severity, actively exploited flaw hit our network-access control platform. Here is our exposure, our patch status and our compromise-assessment result.”

The BOD 26-04 lesson

Unauthenticated, network-reachable, actively exploited, total technical impact. That is exactly the combination BOD 26-04 puts on a three-day clock. Private-sector teams have no legal deadline, but the risk logic is identical. If your internal SLA for this profile is measured in weeks, this week is the argument for changing it.

Get the DataWater Executive Threat Briefing

The threats that changed your risk picture, delivered to your inbox.

Subscribe →

Frequently Asked Questions

What is CVE-2026-76460?

A maximum-severity (CVSS 10.0) authentication bypass in an API endpoint of Cisco Identity Services Engine and ISE-PIC. An unauthenticated remote attacker can send a crafted request to gain unauthorized access, and successful exploitation may result in root command execution.

Is it being exploited?

Yes. Cisco’s PSIRT says it is aware of active exploitation, and CISA added the flaw to its Known Exploited Vulnerabilities catalog.

Is there a workaround?

No workaround fixes the flaw. Infrastructure access control lists that limit traffic to the device prevent remote exploitation until you can upgrade.

Which versions fix it?

ISE and ISE-PIC 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11 and 3.1 Patch 12. ISE 3.0 has reached end of software maintenance, so those customers must move to a supported release.

How do I know if I was compromised?

Review access.log on every node for unusual usernames, and check network and firewall logs outside the appliance for unexpected data transfers. Because attackers with root can erase indicators, treat off-box evidence as more reliable. If in doubt, re-image.

Sources: SecurityWeek · BleepingComputer · The Register · Infosecurity Magazine · Qualys ThreatPROTECT · CISA BOD 26-04. Facts current as of Sept 18, 2026. Exploitation details are still developing; verify against Cisco’s advisory before acting. Informational only.

Similar Posts