Cisco Patches Critical Vulnerability in Identity Services Engine
Cisco has fixed a high-severity vulnerability in its Identity Services Engine (ISE) that is being actively exploited in attacks. ISE is Cisco's Network Access Control (NAC) and identity-based policy platform, which decides who or what is allowed onto a company's network.
The bug, tracked as CVE-2026-76460, was given a severity score of 10/10 (critical) and affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration.
Cisco's Product Security Incident Response Team (PSIRT) is aware of active exploitation and urged customers to upgrade to a fixed software release as soon as possible. There are no workarounds available for this flaw, and a patch is the only solution.