Security & Risk6 minNewsroom

Cisco ISE: CVSS 10 flaw exploited, CISA gives 3 days to patch

Sala de operações de rede em madrugada com analista diante de terminal mostrando acesso root em servidor Cisco ISE

API authentication bypass in Identity Services Engine allows root access without credentials. Cisco offers no workaround, and CISA included the flaw in KEV with a deadline of September 19.

Cisco announced on September 17 that attackers are actively exploiting a CVSS 10.0 flaw in the Identity Services Engine (ISE), the network access policy server used by banks, carriers, and public agencies worldwide. The bug, identified as CVE-2026-76460, allows an unauthenticated attacker to send a forged request to an API endpoint and gain command execution with root privileges, bypassing the web administration interface.


Cisco’s own incident response team (PSIRT) discovered the issue in a customer support ticket, according to consistent reports from SecurityWeek, The Hacker News, and The Register. There is no workaround: the only solution is to upgrade to version 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4. All versions between 3.0 and 3.5 of the ISE and ISE Passive Identity Connector are affected, regardless of network configuration.


CISA Issues Emergency Directive


The Cybersecurity and Infrastructure Security Agency included CVE-2026-76460 in the Known Exploited Vulnerabilities catalog on September 16 and issued an order for U.S. civil executive agencies to apply the patch within three days, with a deadline of September 19. This is the second emergency directive from CISA regarding Cisco vulnerabilities in just over two weeks, signaling that the vendor’s identity and edge devices have become a priority target for groups capable of exploiting zero-days.


The risk extends beyond the delayed patch. ISE stores admission policies for VPN, corporate Wi-Fi, and 802.1X access, and an attacker with root access can delete logs, create phantom users, and issue valid internal certificates. This translates to a loss of forensic evidence precisely where post-incident audits typically reconstruct the attack timeline, compromising both immediate response and mandatory communication to regulators in banks and carriers.


Implications for Non-U.S. Banks and Carriers


The CISA alert is linked only to U.S. federal agencies, but the installed base of ISE is global. European carriers like Deutsche Telekom, Orange, and Vodafone use the product in their network authentication cores. In India, integrators such as TCS and Infosys maintain ISE environments for financial clients in delivery centers in Bangalore and Pune. Brazilian banks also operate ISE in corporate access segments and branch networks, putting security teams on a tight schedule to apply patches in environments with little tolerance for downtime.


The practical issue for banks and telcos is the same trap seen during the wave of Cisco SD-WAN exploitation in the first half of the year: production environments with active-passive clusters require scheduled maintenance, and many teams prefer to accept a risk for 48 hours rather than interrupt authentication for thousands of users. According to SecurityWeek, this is the sixth exploratory zero-day affecting Cisco’s base in 2026, a frequency that undermines the argument that updates can wait for the next monthly window. Five of these six cases affected products in the identity and edge network lines, rather than collaboration stacks or traditional servers.


What This Means for the CIO


For technology and security executives, CVE-2026-76460 has three immediate implications. First is the recognition that the identity surface is now as much of a target as the data perimeter. AAA servers have been treated for years as auxiliary infrastructure, and this incident shows that a bug in an administration API can grant an attacker more access than a successful phishing attempt against a high-privilege user.


The second implication is the window between disclosure and exploitation. Cisco confirmed that exploitation began before public notice, which diminishes the effectiveness of strategies based on a 30-day SLA for production. The third is the actual cost of vendor lock-in with network identity providers: the ISE codebase has shared affected versions between 3.0 and 3.5, with no runtime mitigation options, necessitating a scheduled shutdown in the network admission cluster.


Those managing hybrid environments should undertake at least two actions before Tuesday: check the exposure of ISE ERS/APIs to the internet and correlate administrative access logs with IPs outside the expected range. This year’s pattern of zero-days in identity platforms raises an uncomfortable question for CISOs still treating AAA servers as black boxes operated by the network team: the cost of moving this surface under the same patch regime as business applications is no longer optional.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk