Cisco Patches Critical Flaw in Identity Services Engine Platform
Cisco has patched a critical vulnerability in its Identity Services Engine (ISE) platform, which is used for enterprise network access control and policy enforcement. The flaw, tracked as CVE-2026-76460, has a maximum severity score of 10.0 on the CVSS scale and can be exploited without authentication to gain root-level privileges on the device.
The vulnerability affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC) in all configurations and was fixed in versions 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4.
The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, indicating that exploitation in the wild has been confirmed.