Cisco confirmed this month that hackers were actively exploiting two separate zero-day vulnerabilities in its enterprise software before patches were available, including one flaw that scored a perfect 10.0 on the industry's severity scale.
The more severe bug, tracked as CVE-2026-76460, affects Cisco's Identity Services Engine (ISE) and its Passive Identity Connector, software many large organizations use to control which people and devices can reach their networks. The flaw stems from insufficient authentication checks on an API endpoint; by sending a single crafted request, an attacker with no credentials at all can bypass ISE's web management interface and ultimately execute commands with root privileges, according to Cisco's advisory and reporting from The Hacker News.
Once inside, an attacker could rewrite network access policies, pull stored credentials, delete audit logs and move laterally across every network segment the compromised ISE instance controls — reach that makes the platform a valuable target inside corporate networks. Cisco says it is aware of active exploitation but has not disclosed who is behind the attacks or how many organizations have been hit.
A second flaw, and a short patch window
Separately, Cisco disclosed CVE-2026-76461, a critical SQL-injection flaw in its Secure Email Gateway software that also allows unauthenticated remote code execution as root, this one triggered by a specially crafted email sent through a vulnerable gateway. That bug carries a CVSS score of 9.8 and, like the ISE flaw, was already being exploited before Cisco shipped a fix, according to BleepingComputer.
The federal Cybersecurity and Infrastructure Security Agency added both bugs to its Known Exploited Vulnerabilities catalog in mid-September, giving civilian agencies just three days to patch — an unusually tight window that signals how seriously the government is treating the pair of flaws.
Cisco has released fixed versions for ISE (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4) and is urging customers still running the unsupported 3.0 branch to migrate immediately, since no patch is coming for that release. No workaround fully closes the ISE hole; Cisco says restricting management-interface traffic with access control lists can reduce exposure until systems are updated. Administrators are also advised to check access logs for suspicious activity and, if compromise is suspected, to re-image affected devices rather than trust they can be cleaned in place.