Cisco ISE Zero-Day Vulnerability Allows Unauthenticated Root Command Execution
Cisco's Identity Services Engine (ISE) has been hit with a severe zero-day vulnerability, tracked as CVE-2026-76460. The flaw allows an unauthenticated attacker to send one crafted HTTP request and gain root command execution on the appliance. This means that even without any credentials, an attacker can execute commands on the ISE device.
The issue was discovered by Cisco's Product Security Incident Response Team (PSIRT) while working a support case with a customer who had already been hit by the bug. The team confirmed that attackers were exploiting the vulnerability in real-world scenarios before the patch was released. In fact, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog just one day after disclosure.
Cisco has patched the issue with a series of emergency patches, but the company's own language suggests that attackers were already inside customer networks using this bug. This is not an isolated incident - Cisco recently patched another actively exploited flaw in its Secure Email Gateway product.