Cisco Patches Critical ISE Flaw Under Active Attack Before Discovery
Cisco has patched a maximum-severity flaw in its Identity Services Engine (ISE) and ISE Passive Identity Connector, which allows attackers to gain full access to the appliance's web-based management interface without any authentication. The bug, identified as CVE-2026-76460, has a CVSS score of 10.0, indicating it requires no password or session token for exploitation.
Cisco confirmed that hackers were actively exploiting the flaw before it was even discovered by the company's security team, which found the issue while resolving a customer support ticket. The vulnerability affects ISE and ISE-PIC releases 3.0 through 3.5 and allows attackers to execute commands with root privileges, move laterally into network segments, and delete logs.
Cisco has released patches for five separate branches of its software, but security experts warn that the window for patching is narrow, with federal civilian agencies given only until September 19 to apply the fixes. The flaw highlights the increasing risk of AI-agent-assisted intrusions in the industry, as attackers move faster from disclosure to exploitation than ever before.
For enterprise security teams, the math is clear: every day ISE sits unpatched is a day the front door has no lock, and the attacker doesn't even need to pick it. Cisco has not disclosed how many organizations were compromised before the advisory went out, but the urgency of the situation is clear.