HomeComputing

Computing

Cisco ISE Zero-Day With CVSS 10 Is Being Exploited: Patch Guidance for Admins

Cisco has patched CVE-2026-76460, a maximum-severity ISE authentication-bypass flaw that requires no credentials and has been added to CISA's exploited-vulnerability catalog.

Cisco logo representing an Identity Services Engine security advisory
Cisco logo representing an Identity Services Engine security advisory
Research-based guidePrimary references and a decision framework are included below.How we research →

Cisco has released fixes for a maximum-severity vulnerability in Identity Services Engine that security teams should treat as an urgent patching problem rather than another item in a long monthly update list.

The flaw, tracked as CVE-2026-76460, carries a CVSS base score of 10.0. Cisco says it exists in an API used by Identity Services Engine, or ISE, and can allow an unauthenticated remote attacker to bypass authentication.

That combination is serious on its own. The risk rises further because government security guidance now identifies the vulnerability as exploited in the wild.

The Canadian Centre for Cyber Security says CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog on September 16. Cisco's own advisory says there are no workarounds that address the vulnerability.

Why ISE is a high-value target

Cisco ISE is not an ordinary endpoint application.

Organizations use it for identity and access policy across enterprise networks. Depending on the deployment, it can sit near decisions about which users, devices and systems are allowed onto a network and what access they receive.

That makes a remote authentication-bypass vulnerability particularly sensitive. A weakness in a central identity or policy system can create opportunities that are much broader than compromising a single laptop.

Cisco says the vulnerability is caused by insufficient validation in an API. An attacker does not need credentials or user interaction to exploit it under the conditions described by the advisory.

Security teams should read the exact vendor advisory for their deployment rather than relying on headlines alone, because affected software branches and fixed patch levels differ.

There is no complete workaround

One of the most important lines in Cisco's advisory is also one of the least convenient: there are no workarounds that address this vulnerability.

That does not mean administrators are powerless while a change window is being prepared. They can reduce exposure, restrict management access, monitor unusual requests and review network segmentation.

But those are compensating controls, not substitutes for the fixed software.

When a vendor explicitly says no workaround fully resolves an actively exploited CVSS 10 vulnerability, the normal argument for waiting until the next routine maintenance cycle becomes much weaker.

Which versions need attention

The Canadian Cyber Centre alert lists affected Cisco ISE branches and the patch levels organizations should move beyond.

The advisory includes ISE 3.1, 3.2, 3.3, 3.4 and 3.5 lines, with specific patches required depending on the branch. ISE-PIC is also included.

Administrators should verify their exact version directly in Cisco documentation before making changes. Security advisories can be updated, and enterprise products frequently have support constraints that make a simple "install the latest version" instruction insufficient.

The same September Cisco security release also covers other products including Secure Firewall and Nexus Dashboard, but CVE-2026-76460 stands out because of its severity and known exploitation.

What organizations should do now

First, inventory every ISE and ISE-PIC deployment, including systems that may not be internet-facing.

"Not public on the internet" is useful risk reduction, but it does not make a vulnerable identity appliance harmless. Attackers who already have a foothold in an enterprise network can target internal infrastructure.

Second, compare each deployment against Cisco's fixed versions and schedule emergency patching where necessary.

Third, preserve logs around the vulnerable systems. If exploitation has already occurred, patching prevents future use of the flaw but does not automatically tell the organization whether an attacker was present before the update.

Teams should review authentication activity, administrative events, unusual API requests and network connections around the appliance according to their own logging architecture.

Why known exploitation changes prioritization

Security teams routinely face more vulnerabilities than they can patch immediately. Severity scores help, but they are not enough on their own.

A CVSS 10 vulnerability that is difficult to reach may be less urgent in one environment than a lower-scored flaw that attackers are actively using against exposed systems.

Here, the signals align: maximum severity, remote unauthenticated exploitation, a central security product and known exploitation.

That is exactly the type of vulnerability that risk-based patch programs are designed to move ahead of lower-priority maintenance.

The larger lesson for identity infrastructure

Enterprises often focus security attention on internet-facing web applications and employee endpoints. Identity, network-access and management systems can be even more consequential because they influence many other assets.

An ISE server may not be visible to ordinary employees, but its role in enforcing access makes it part of the security control plane.

For organizations running affected versions, the action is straightforward even if the operational work is not: verify the Cisco advisory, test the appropriate fixed release and patch quickly.

With no complete workaround and evidence of exploitation, this is not a vulnerability to leave for a future quarterly maintenance window.

Editorial research note

How we reached this guidance

We reviewed Cisco's security advisory and the Canadian Centre for Cyber Security alert summarizing affected versions and CISA KEV status. We describe exploitation as confirmed through the public government alert and avoid speculating about attackers or victim organizations.

Decision framework

ScenarioRecommendationWhy
An organization runs an affected Cisco ISE or ISE-PIC versionApply Cisco's fixed release as an emergency changeThe vulnerability has a CVSS score of 10.0, can be exploited remotely without authentication and has been added to the known-exploited catalog.
A team cannot patch immediatelyEscalate compensating controls and exposure reductionCisco says there are no workarounds that fully address the flaw, so delaying the vendor fix leaves residual risk.
Administrators are prioritizing a large September patch queueMove CVE-2026-76460 near the topActive exploitation changes the risk from hypothetical to operational.

Primary references

Reviewed on September 17, 2026. Unless an article explicitly states that TECHMUNDI performed hands-on testing, our guides are research-based and do not present specification or documentation review as first-hand product testing.