Cisco ISE CVE-2026-76460: CVSS 10.0 auth bypass exploited in the wild
Cisco patched CVE-2026-76460 (CVSS 10.0) in Identity Services Engine and ISE-PIC, where an unauthenticated attacker can reach a management API endpoint and gain root-level command execution. Exploitation was confirmed in the wild and CISA added the flaw to its Known Exploited Vulnerabilities catalog with a September 19, 2026 deadline.
- CWE-648 flaw is configuration-independent and yields root on the ISE appliance
- Fixes: ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4
- ISE 3.0 is vulnerable but past end of maintenance, requiring migration
- CISA set a three-day federal deadline; Cisco recommends reimaging compromised nodes
Read next
Security