SAN JOSE, Calif. — Cisco has confirmed that attackers are actively exploiting a maximum-severity authentication bypass flaw in its widely used Identity Services Engine (ISE) network access control software, and has released emergency patches after the US Cybersecurity and Infrastructure Security Agency (CISA) added the bug to its Known Exploited Vulnerabilities catalog this week.
Key Highlights
- The flaw, tracked as CVE-2026-76460, carries the maximum possible CVSS score of 10.0.
- It affects Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), software that enterprises and government agencies use to control which devices and users can access their networks.
- Cisco’s own security team, Cisco PSIRT, says it is “aware of active exploitation” of the flaw in real-world attacks.
- A successful attack lets an unauthenticated, remote attacker bypass ISE’s web-based management interface entirely and execute commands with root privileges.
- CISA added the bug to its Known Exploited Vulnerabilities (KEV) catalog on September 16, ordering US federal agencies to patch on an accelerated timeline.
- There is no workaround. Cisco says the only fix is to upgrade to a patched software release.
Latest Development
Cisco disclosed CVE-2026-76460 this week as part of a broader security hardening release covering its ISE product line, but flagged this specific flaw separately because it is already being exploited. In its advisory, Cisco said the vulnerability stems from “insufficient authentication control on an API endpoint” in ISE, meaning an attacker does not need any valid credentials to send a crafted request to the vulnerable endpoint and gain access. Cisco PSIRT said in its advisory that it is “aware of active exploitation of this vulnerability” and “strongly recommends that customers upgrade to a fixed software release” without delay. Security researchers tracking the campaign have advised administrators to check access logs for suspicious or unfamiliar usernames, including one associated with early exploitation attempts, as a possible indicator of compromise.
What Happened
Cisco ISE is a network access control (NAC) platform used by large enterprises, banks, universities and government agencies to enforce who and what can connect to their internal networks — verifying device identity, applying security policy, and granting or denying access accordingly. Because ISE effectively sits as a gatekeeper in front of an organisation’s network, a flaw that lets an outsider bypass its authentication is considered especially dangerous: rather than simply stealing data from one application, an attacker who compromises ISE can potentially manipulate the access-control decisions for an entire corporate network.
According to Cisco and independent security researchers, the vulnerability allows an unauthenticated remote attacker to bypass ISE’s web-based management interface by sending a specially crafted request to an exposed API endpoint. From there, the attacker can obtain command execution with root-level privileges on the underlying device — the highest level of system access — which researchers say could also let intruders erase logs or other evidence of their intrusion. Cisco has published fixes across every actively maintained ISE branch: version 3.1 (Patch 12), 3.2 (Patch 11), 3.3 (Patch 12), 3.4 (Patch 7) and 3.5 (Patch 4). Devices running ISE 3.0 or earlier are no longer supported and must be migrated to a current release to be secured.
Background
The disclosure lands amid a difficult stretch for enterprise network security vendors, with several major vendors disclosing actively exploited zero-days in edge and access-control products over the past year as attackers increasingly target the infrastructure that sits at the perimeter of corporate networks rather than end-user applications. Cisco ISE in particular is deployed extensively across large organisations globally, including in India’s banking, IT services and telecom sectors, where it is commonly used alongside firewalls and identity providers to enforce zero-trust network access policies.
CISA’s Known Exploited Vulnerabilities catalog is a running list of software flaws the US government has confirmed are being actively used in real attacks; its Binding Operational Directive requires US federal civilian agencies to patch catalog entries within a set window, currently within three days for the most urgent entries, underscoring how seriously US authorities are treating this particular flaw.
Why It Matters
A maximum-severity, unauthenticated remote code execution flaw in a network access control product is close to a worst-case scenario for enterprise security teams, because ISE deployments are often trusted to make access decisions for thousands of devices at once. Any organisation running an affected, unpatched version is a potential target for as long as it remains unpatched, and because exploitation requires no valid login credentials, standard password-based defences offer no protection.
India and Asia Impact
Cisco networking equipment, including ISE, is widely deployed across Indian and Asian enterprises, banks and telecom operators that rely on it to secure office and data-centre networks. Organisations in the region running Cisco ISE should treat this as an urgent patching priority rather than a routine update, given that the flaw is already being exploited and requires no stolen password or insider access to trigger. IT security teams are typically advised to check whether their deployed version falls in the affected range, apply Cisco’s patches immediately, and review access logs for signs of prior compromise, since attackers who gained access before a system was patched may still retain a foothold.
What Happens Next
US federal agencies face a compressed deadline to patch under CISA’s directive, and security researchers expect exploitation attempts to increase now that the vulnerability and patch are both public, a common pattern once a proof-of-concept becomes easier for less sophisticated attackers to replicate. Cisco has not publicly attributed the exploitation to a specific hacking group. Organisations that cannot patch immediately are being advised to restrict access to ISE’s management interface using infrastructure access control lists (iACLs) as a stopgap, though Cisco stresses this is not a substitute for installing the fix.
Sources / References
- The Hacker News — “Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks”
- SecurityWeek — “Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day”
- BleepingComputer — “Cisco warns of Identity Service Engine zero-day exploited in attacks”
- Cisco Security Advisory — ISE Hardening Release, September 2026
Related on The Press of Asia: India’s 1,000-km quantum communication breakthrough for unhackable networks and OpenAI’s new framework for disclosing AI model security incidents.
📩 Never miss a story: Get breaking news and in-depth Asia business coverage delivered to your inbox — subscribe to The Press of Asia newsletter.
