Cisco Warns of Critical Vulnerability in Identity Services Engine
Cisco has warned of a critical security vulnerability impacting its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), which has been actively exploited by attackers.
The vulnerability, tracked as CVE-2026-76460 with a CVSS score of 10.0, allows an unauthenticated remote attacker to bypass authentication, granting unauthorized access to the affected device's web-based management interface.
Cisco emphasized that there are no workarounds and urged customers to upgrade to fixed software releases immediately, citing active exploitation of the flaw.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog on September 16, requiring Federal Civilian Executive Branch agencies to apply patches by September 19.