Cisco discloses actively exploited, maximum-severity flaw in its network access control software
The company says attackers were already exploiting the vulnerability before a patch existed, and federal regulators have ordered civilian agencies to fix it within days.

Cisco disclosed on Wednesday that hackers were already exploiting a maximum-severity flaw in Identity Services Engine, the software many large companies and government agencies use to decide which devices and users are allowed onto their networks. The vulnerability, tracked as CVE-2026-76460, lets an attacker with no credentials at all seize control of the appliance that is supposed to be guarding the network's front door.
Cisco's own advisory put it plainly: the company's Product Security Incident Response Team said it was "aware of active exploitation of this vulnerability" before a fix was even available, meaning some customers were compromised during the window when the flaw was known only to attackers.
A perfect score, and no way around it
The bug carries a CVSS score of 10.0, the highest rating the industry's severity scale allows, reflecting that it requires no authentication, no user interaction and can be triggered remotely over the network. According to Cisco, an unauthenticated attacker can send a specially crafted request to an exposed API endpoint and bypass the product's web-based management login entirely. From there, Cisco warned, successful exploitation "may result in root-level command execution" — full control of the machine, not just a peek inside it.
There is no workaround. Cisco's advisory says the only real fix is to install a patched release: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 or 3.5 Patch 4, depending on which version a customer is running. Anyone still on ISE 3.0, which reached the end of its support life, has to move to a newer branch altogether. Short of patching, Cisco recommends restricting access to the appliance with infrastructure access-control lists, and it published forensic guidance telling administrators to comb through access logs for suspicious usernames — while cautioning that attackers with root access can delete or fake that same evidence.
How it surfaced
Unusually for a zero-day, this one was not found by an outside security researcher chasing a bug bounty. Cisco's advisory says the flaw "was found during the resolution of a Cisco Technical Assistance Center (TAC) support case" — in other words, a customer's own support ticket led engineers back to the underlying defect, after which the company discovered attackers were already using it in the wild.
The disclosure landed alongside an unusually large batch of other fixes. On the same day, Cisco published a batch of advisories covering roughly 77 new CVEs across its Identity Services Engine and Secure Firewall product lines, including a separate "hardening release" bundling six additional ISE vulnerabilities — two of them also rated a full 10.0 — that Cisco says its engineers found through internal review rather than active attacks. Cisco has said it now assigns a single bundled CVE to each underlying weakness category rather than issuing one advisory per bug, a shift the company's security leadership attributed earlier this year to AI tools now finding far more flaws, far faster, than the old one-advisory-at-a-time process could handle. "Manual, one-off advisories at unpredictable intervals are no longer the right tool for the job," Russ Smoak, Cisco's vice president of security assurance and response, wrote in that explanation.
A repeat target
Identity Services Engine has now had three separate vulnerabilities reach the maximum 10.0 severity score since June 2025, following CVE-2025-20337 and CVE-2025-20281, both of which were also exploited before patches were widely deployed. The new flaw arrived a single day after Cisco disclosed a different actively exploited zero-day, CVE-2026-76461, in its unrelated Secure Email Gateway product — the company's second emergency disclosure in as many days, though researchers say the two bugs are not connected.
The repeated targeting reflects what ISE actually controls. The software sits at the center of network-access policy for wired, wireless and VPN connections, deciding which devices get in and what they are allowed to reach once inside. That makes it a high-value target: compromise the gatekeeper, and an attacker inherits the keys to everything it was guarding.
"ISE devices enforce network access policy, so root access on the appliance lets an attacker modify that policy, extract stored credentials, delete logs, and move laterally into every network segment ISE controls," said Landon Rice, a senior exploit developer at the security firm VulnCheck.
Who has to move now
The vulnerability affects any Cisco ISE or ISE Passive Identity Connector deployment "regardless of device configuration," according to the advisory, which covers a wide swath of corporate, university and government networks that rely on Cisco's gear for network-access control. The National Vulnerability Database entry confirms the same maximum score and lists the flaw as newly published this week.
The U.S. Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalog on the day of disclosure, a designation reserved for flaws with confirmed real-world attacks. That listing requires federal civilian agencies to patch by September 19 — a three-day turnaround that underscores how little runway CISA believes defenders have. Private companies face no such deadline, but security researchers have been urging the same pace, given that Cisco itself has confirmed exploitation predates the fix.
Coverage of the disclosure has not identified the attackers behind the exploitation, and Cisco has released no estimate of how many devices were breached before the patch shipped. SecurityWeek reported that Cisco is continuing to work with affected customers and has not ruled out further disclosures tied to the same investigation.
For now, the burden falls on network administrators to patch immediately, audit their logs for the indicators Cisco published, and assume that any unpatched, internet-reachable ISE deployment should be treated as already compromised until proven otherwise. With the flaw now public and a patch available for defenders to reverse-engineer, security researchers expect exploitation attempts to broaden quickly among organizations that have not yet updated.

Apple's First Launch Under New CEO Ternus Pairs iPhone 18 Pro With Gemini-Built Siri
Waymo to bring driverless robotaxis to Singapore by 2028
Microsoft Rushes Emergency Windows 11 Fix After Record Patch Breaks PCs
