Cisco's Identity Services Engine Hit by Critical CVE-2026-76460 Vulnerability
Cisco's Identity Services Engine (ISE) has been hit by a critical vulnerability, CVE-2026-76460, which allows attackers to bypass authentication and gain access to sensitive areas of the system. The bug, discovered on September 16, 2026, was so severe that the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalog just two days later, giving federal civilian agencies a one-day deadline to patch the issue.
The vulnerability affects ISE versions 3.0 through 3.5, with no workaround available for organizations that cannot patch immediately. Successful exploitation can lead to command execution with root privileges on the underlying appliance, allowing attackers to read stored credentials and secrets, rewrite access policies, create rogue administrative accounts, and disrupt the authentication service.
Cisco's Product Security Incident Response Team (PSIRT) reported that it was already seeing active exploitation of the bug prior to the patch shipping, making this a zero-day vulnerability. The company recommends reimaging any node where compromise is suspected rather than trusting an in-place upgrade to fully remove an attacker's foothold.
This is not an isolated incident for Cisco ISE, as two other maximum-severity bugs were disclosed in June 2025, tracked as CVE-2025-20337 and CVE-2025-20338. The frequency of these high-severity vulnerabilities in a single product line raises concerns about the security posture of organizations relying on identity infrastructure.