Cisco warned on September 16, 2026, about active attacks targeting a critical Cisco ISE vulnerability. The security flaw allows unauthenticated remote attackers to bypass web authentication and seize root privileges. Consequently, administrators must update their systems immediately to stop intrusions.
Track every Cisco CVE the moment it's exploited.
Get free email alertsTL;DR
Cisco resolved a maximum-severity flaw in its Identity Services Engine. Attackers are actively exploiting this security defect in the wild. System administrators must apply vendor patches immediately to prevent unauthorized access.
Why This Threat Matters
Sourced estimates indicate that tens of thousands of organizations deploy Cisco ISE for network access control. The platform enforces identity policies across critical enterprise networks. Therefore, compromising this server grants attackers wide access to internal resources. The advisory notes, “The Cisco PSIRT is aware of active exploitation of this vulnerability.” An intruder can manipulate access rules and pivot deeper into private corporate subnets.
How the Attack Works
Tracked as CVE-2026-76460, the flaw carries a maximum CVSS score of 10.0. The security advisory states, “This vulnerability is due to insufficient authentication control on an API endpoint.” An attacker sends crafted network requests directly to an exposed endpoint. As a result, the request bypasses the web management interface. Threat actors can then execute commands with root privileges. Furthermore, attackers can erase log entries to conceal their actions. Cisco discovered the bug while resolving a Technical Assistance Center support case.
Affected Versions
This critical Cisco ISE vulnerability impacts Cisco ISE and Cisco ISE-PIC across all device configurations. Specifically, releases 3.1 through 3.5 remain affected. Cisco confirmed active exploitation in the wild.
Patch and Mitigation Steps
Administrators must patch this Cisco ISE vulnerability by deploying fixed releases immediately. Cisco released software updates, including 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. There are no temporary workarounds. However, defenders can use infrastructure access control lists to block untrusted traffic. Additionally, teams should inspect access logs for suspicious dummyuser account entries.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!