Cisco has warned that a maximum-severity authentication-bypass vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) β tracked as CVE-2026-76460 with a CVSS score of 10.0 β is under active exploitation. The flaw, caused by insufficient authentication control on an API endpoint, lets an unauthenticated remote attacker send a crafted request to bypass the web-based management interface; Cisco says successful exploitation can yield root-level command execution, which also means evidence of compromise may be removed or hidden. There are no workarounds; Cisco urges upgrade to a fixed release (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 or 3.5 Patch 4) and, as an interim mitigation, infrastructure ACLs limiting management traffic. CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 16 September, giving federal civilian agencies a 19 September remediation deadline. The advisory arrives inside a 77-CVE Cisco batch dominated by ISE and the Secure Firewall portfolio, several at CVSS 9.8β10.0 but not yet listed as exploited. The disclosure follows days after Cisco flagged a separately exploited Secure Email Gateway flaw (CVE-2026-76461).
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-18 |
| Source | The Hacker News |
| Reliability | Tier 2 |
| CVEs | CVE-2026-76460, CVE-2026-76461 |