A critical zero-day vulnerability, tracked as CVE-2026-76460, is currently being exploited in the wild targeting Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC). Rated with a maximum CVSS score of 10.0, the flaw enables unauthenticated remote attackers to bypass authentication mechanisms, granting unauthorized access to core identity infrastructure. Successful exploitation permits attackers to manipulate Network Access Control (NAC) policies, effectively compromising the entire network admission process. Given the active exploitation and extreme severity, CISA has issued an emergency directive requiring federal agencies to apply security patches by September 19, 2026, to mitigate the risk of full identity infrastructure takeover.
-
Vulnerability Overview
- Targeted Software: Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC).
- Severity Rating: CVSS 10.0 (Critical/Maximum).
- Exploitation Status: Active zero-day exploitation observed in live environments.
-
Vulnerability Mechanics
- Exploit Vector: Unauthenticated remote access via network-facing interfaces.
- Technical Flaw: Authentication bypass vulnerability allowing attackers to circumvent identity verification.
- Access Level: Provides unauthorized entry into the identity control plane and NAC management.
-
Impact & Threat Landscape
- Infrastructure Compromise: Direct threat to the integrity of Network Access Control (NAC) and enterprise identity systems.
- Recurring Threat Profile: This marks the third actively exploited Cisco ISE vulnerability since June 2025.
- Operational Risk: Potential for attackers to authorize rogue devices or escalate privileges across the network.
-
Mitigation & Regulatory Response
- CISA Mandate: Urgent patching deadline of September 19, 2026, for all federal agencies.
- Primary Remediation: Immediate deployment of Cisco Emergency Security Updates and official patches.
- Defense Priority: Critical priority for all organizations utilizing ISE for network admission and identity management.
-
Strategic Defensive Conclusion
- Risk Trend: Increasing targeting of centralized identity management stacks by sophisticated actors.
- CISO Guidance: Validate patch compliance across all ISE/ISE-PIC nodes and monitor authentication logs for anomalous patterns.
Related posts
- bleepingcomputer.com — Cisco warns of max severity ISE zero-day exploited in attacks
- datawater.com — The System That Decides Who Gets on Your Network Is Under Active Attack — Cisco ISE Zero-Day Hits CVSS 10.0, and CISA’s Deadline Is Tomorrow
- Thehackernews
- socprime.com — CVE-2026-76460: Critical Cisco ISE Zero-Day Authentication Bypass Exploited in the Wild
- cyberscoop.com — Cisco alerts customers to second actively exploited zero-day in as many days
- Rodtrent
- Techradar
- SecurityWeek — Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day