Security News

Cisco Warns Critical ISE Flaw Is Being Actively Exploited

Infosecurity Magazine · 17 Sept 2026
Key Takeaway If your business uses Cisco ISE or ISE-PIC, patch immediately and check access logs for suspicious activity, as delaying could allow attackers root level control of your network access system.

Cisco has warned that a maximum severity flaw in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products is being actively exploited by attackers. The vulnerability, tracked as CVE-2026-76460, carries the highest possible severity score of 10.0 and stems from insufficient controls on an API endpoint. Attackers can exploit it by sending a specially crafted request, allowing them to bypass the web based management interface and gain unauthorised access to the device, regardless of how it is configured.

Cisco has released software updates to fix the flaw and is urging all customers to upgrade immediately, as no workaround fully resolves the issue. In the meantime, organisations can use infrastructure access control lists to restrict management traffic to the affected devices, reducing the risk of remote exploitation before patches are applied. The US Cybersecurity and Infrastructure Security Agency has added this vulnerability to its Known Exploited Vulnerabilities catalog, requiring US federal agencies to patch it as a priority.

Cisco has also advised customers to check their systems for signs of compromise by reviewing access logs for suspicious usernames. Because successful exploitation can give attackers root level access, potentially allowing them to erase evidence of the intrusion, Cisco recommends that any suspected compromised devices be re-imaged and restored from a clean configuration backup.

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.