Cisco ISE Vulnerability Exposes Root-Level Access
A critical vulnerability has been discovered in Cisco's Identity Services Engine (ISE), allowing unauthenticated remote attackers to gain root-level access and potentially wipe system logs. The flaw, known as CVE-2026-76460, has a CVSS score of 10.0, making it a high-priority threat that requires immediate attention.
The vulnerability affects Cisco ISE releases 3.0 through 3.5, with the only effective mitigation being the application of patches or strict infrastructure access control lists (iACLs). The Cisco Product Security Incident Response Team (PSIRT) has confirmed active exploitation in the wild, and the CISA Known Exploited Vulnerabilities catalog includes the flaw.
Organizations that rely on Cisco management-plane infrastructure, including crypto firms, CEX/Custodians, and DeFi operators, are at risk of immediate security threats. These entities must prioritize patching and external network-level monitoring to protect their custody, operations, and token launch plans.