Cisco Issues Urgent Warning on Active Exploitation of Critical ISE Flaw
Cisco has issued an urgent warning to customers about the active exploitation of a critical flaw in its Cisco Identity Services Engine (ISE) product. The vulnerability, CVE-2026-76460, has a maximum CVSS rating of 10.0 and allows attackers to gain unauthorized access by bypassing the web-based management interface.
The company released software updates to address the issue and urged customers to upgrade as soon as possible. There are no workarounds available, but customers can use infrastructure access control lists (iACLs) to prevent remote exploitation prior to applying the update.
Cisco ISE is a centralized security policy management platform that controls network access across wired, wireless, and VPN connections. The US Cybersecurity and Infrastructure Agency (CISA) has added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to prioritize applying a patch for the vulnerability.