Critical Authentication Bypass Zero-Day in Cisco Identity Services Engine ISE
A critical zero-day vulnerability, tracked as CVE-2026-76460, is currently being exploited in the wild targeting Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC). Rated with a maximum CVSS score of 10.0, the flaw enables unauthenticated remote attackers to bypass authentication mechanisms, granting unauthorized access to core identity infrastructure. Successful exploitation permits attackers to manipulate Network Access Control (NAC) policies, effectively compromising the entire network admission process. Given the active exploitation and extreme severity, CISA has issued an emergency directive requiring federal agencies to apply security patches by September 19, 2026, to mitigate the risk of full identity infrastructure takeover.