Home Β· Wiki Β· Incidents & Campaigns
type: incident Β· created: 2026-09-18 Β· updated: 2026-09-18 Β· tags: [incident, government, zero-day] Β· confidence: high Β· severity: critical Β· affected_sectors: [government] Β· au_impact: true

Cisco has warned that a maximum-severity authentication-bypass vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) β€” tracked as CVE-2026-76460 with a CVSS score of 10.0 β€” is under active exploitation. The flaw, caused by insufficient authentication control on an API endpoint, lets an unauthenticated remote attacker send a crafted request to bypass the web-based management interface; Cisco says successful exploitation can yield root-level command execution, which also means evidence of compromise may be removed or hidden. There are no workarounds; Cisco urges upgrade to a fixed release (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 or 3.5 Patch 4) and, as an interim mitigation, infrastructure ACLs limiting management traffic. CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 16 September, giving federal civilian agencies a 19 September remediation deadline. The advisory arrives inside a 77-CVE Cisco batch dominated by ISE and the Secure Firewall portfolio, several at CVSS 9.8–10.0 but not yet listed as exploited. The disclosure follows days after Cisco flagged a separately exploited Secure Email Gateway flaw (CVE-2026-76461).

Attribute Detail
Sector Government
Date 2026-09-18
Source The Hacker News
Reliability Tier 2
CVEs CVE-2026-76460, CVE-2026-76461