CISA Flags Actively Exploited Cisco ISE Flaw With No Workaround
Cisco's Identity Services Engine (ISE) has been hit by a critical vulnerability that allows unauthenticated attackers to execute commands with root privileges.
The issue, tracked as CVE-2026-76460, was added to the Known Exploited Vulnerabilities (KEV) Catalog by the Cybersecurity and Infrastructure Security Agency (CISA) after evidence of active exploitation emerged.
Cisco assigned the flaw a maximum Common Vulnerability Scoring System score of 10.0 in its September 16 security advisory, highlighting the severity of the issue.
The agency has directed federal agencies to remediate affected publicly exposed systems by September 19 and follow forensic triage requirements under Binding Operational Directive (BOD) 26-04.
Cisco has released software updates to address the flaw but warned that no workaround is available, advising administrators to review logs outside the affected appliance due to potential evidence tampering.