Cisco is warning customers of a maximum-severity security flaw in its Identity Services Engine software that attackers are already exploiting, the second actively exploited zero-day the networking giant has disclosed in less than a week.
The vulnerability, tracked as CVE-2026-76460, carries a perfect 10.0 score on the industry's severity scale. It stems from insufficient authentication checks on an application programming interface inside Cisco ISE and its companion product, ISE Passive Identity Connector, which many large organizations use to decide who and what gets access to their networks.
An attacker who sends a specially crafted request to the vulnerable endpoint can bypass the system's web-based management login entirely, according to Cisco's advisory, gaining command execution with root privileges. Because ISE sits at the center of network access policy for many enterprises, that level of control lets an intruder rewrite access rules, pull stored credentials, erase logs and move into other parts of a network ISE is meant to guard.
Cisco confirmed exploitation is already underway but has not said who is behind it or how widely the flaw has been used.
No workaround, only patches
Cisco has released fixes across its supported branches — Patch 12 for ISE 3.1, Patch 11 for 3.2, Patch 12 for 3.3, Patch 7 for 3.4 and Patch 4 for 3.5 — and says no workaround exists short of applying them. Administrators have been advised to check device access logs for suspicious accounts as a sign of possible prior compromise.
The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on September 16, ordering federal civilian agencies to patch within three days — an unusually tight window that underscored how seriously the agency viewed the risk.
It is the third actively exploited, maximum-severity flaw to hit Cisco ISE since mid-2025, following two earlier bugs that attackers used to plant web shells on compromised systems. Cisco disclosed this latest flaw just two days after warning of a separate, unrelated zero-day in its Secure Email Gateway product, a coincidence of timing rather than a connected campaign, according to researchers who reviewed both advisories.
Security researchers say the recurring targeting of ISE reflects its position as a high-value target: compromising the system that decides who belongs on a network offers attackers a foothold that is both broad and hard to detect. With no mitigation available besides patching, incident responders are urging enterprises running ISE to treat the update as immediate rather than routine.