Thought Leadership to Decode Innovation & Accelerate Smart Business Decisions.

Choose Value with Competitive Costs through our IT Outsourcing ROI Calculator. Get Your Report
Hire Pre-Vetted Engineers with 2-weeks, Risk-Free Trial Get Started
Build your own Agentic AI. Book a Slot

Cisco Patches Maximum-Severity Flaw Under Active Attack in Identity Services Engine

Top 7 JavaScript Frameworks to Use in 2025

Cybersecurity  |  Published September 21, 2026  |  Source: The Hacker News / CISA

Cisco disclosed CVE-2026-76460 on September 16, an authentication bypass vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that received the maximum possible CVSS severity score of 10.0. Cisco's Product Security Incident Response Team confirmed the flaw is being actively exploited in the wild.

What the Vulnerability Does

The issue stems from insufficient authentication control on a management API endpoint. An unauthenticated, remote attacker can send a single crafted request to bypass Cisco ISE's web-based management interface entirely — no valid credentials required — and potentially achieve root-level command execution on the affected appliance.

Cisco ISE is widely deployed as a central identity and network-access control platform, meaning a compromised ISE instance can give an attacker visibility and control over policy decisions across an organization's entire network segmentation strategy.

Who's Affected

The vulnerability affects Cisco ISE and ISE-PIC versions 3.0 through 3.5, regardless of deployment configuration. Cisco has released fixed versions (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4), and version 3.0 has reached end of software maintenance, meaning organizations still running it need to migrate to a supported release entirely.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on the same day it was disclosed, giving federal agencies until September 19 to remediate — an unusually tight turnaround that signals how seriously the vulnerability is being treated.

What to Do

Cisco has stated there is no software workaround for this vulnerability. Organizations running affected ISE deployments should patch immediately, and in the meantime can use infrastructure access control lists (iACLs) to restrict management-plane traffic as a temporary, partial mitigation. Given the flaw was already under active exploitation before public disclosure, security teams should also review logs for signs of prior compromise, not just apply the patch and move on.

This summary is based on reporting from The Hacker News, Help Net Security, and Cisco's own security advisory. For complete technical indicators of compromise, refer to Cisco's official advisory.

Author

Explore expert insights, blogs, and technology trends shared by Shalaka Gadgil, a leading voice in digital transformation at Cantonet Technologies.

Table of Contents

Talk To Our Experts

Chat with us on WhatsApp
Cantonet Assistant
Cantonet Technologies
Cantonet Assistant
Online now
Talk to an Expert

Talk to an Expert

Tell us what you need — we'll explain the service and give you an instant ballpark estimate.

Website
Web Application
Mobile App
AI / Custom Software

    Simple
    Moderate
    Complex
    1–2 months
    3–4 months
    5+ months