Cisco Patches Critical Vulnerability in ISE Software Under Active Exploitation
Cisco has released emergency patches for a critical-severity authentication bypass vulnerability in its Identity Services Engine (ISE) software. The vulnerability, tracked as CVE-2026-76460 with a CVSS score of 10/10, allows attackers to send crafted requests to the API and gain access to affected devices.
The flaw affects both Cisco ISE and ISE Passive Identity Connector (ISE-PIC), regardless of device configuration. While no workarounds exist, using infrastructure access control lists (iACLs) can prevent remote exploitation.
Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability. The company has not shared information on who is behind the attacks, but notes that cybercriminals and state-sponsored threat actors regularly target vulnerabilities in its products.