Cybersecurity 5 min read

Cisco Found a 10.0 Identity Services Engine Zero-Day in a Support Case

An authentication bypass on the appliance that decides who gets onto the network, scored 10.0, already being exploited when Cisco published it. There is no workaround.

Kenji Tanaka
Developer Tools & Cloud Analyst
Published 18 Sep 2026, 12:01 PM (SGT)
Share:
Coloured network patch cables with connectors standing upright against a white background Coloured network patch cables with connectors standing upright against a white background Photo by blickpixel on Pixabay
Advertisement

18 SEP 2026 — Cisco found the flaw in a customer support case. By the time it published, someone was already using it.

CVE-2026-76460 scores 10.0, lets an unauthenticated attacker past the management interface of Cisco Identity Services Engine, and is in CISA's Known Exploited Vulnerabilities catalogue with a federal deadline of 19 September.

What the flaw lets through

Cisco describes the cause in one line: "This vulnerability is due to insufficient authentication control on an API endpoint." A crafted request to that endpoint bypasses the web-based management interface, and successful exploitation can reach command execution with root privileges.

Identity Services Engine decides which devices and users are allowed onto the network. An authentication bypass there is not one machine lost; it is the policy engine that grants everyone else their access.

Both ISE and the ISE Passive Identity Connector are affected. There are no workarounds. The only remedy is the patched release.

Found in a support case

Look at how it was found. Cisco has said it discovered the vulnerability while working a technical support case, and that it is aware of active exploitation. It has not said who is exploiting it, against whom, or since when.

The sequence is telling. A customer had a problem, the problem turned out to be an attacker already inside the product, and the disclosure followed. This was not found in a code audit or reported through a bounty programme. It surfaced because someone was already using it.

10.0CVSS, the maximum
19 SepCISA deadline for federal agencies
5Release trains needing patches
NoneWorkarounds available

Not the flaw next door

This is Cisco's second actively exploited zero-day in a matter of days, and the two carry consecutive identifiers. We covered CVE-2026-76461 in Secure Email Gateway earlier this week.

The adjacency is a coincidence of numbering. As CyberScoop reports, the two are unrelated, affecting different products and different vulnerability classes. CVE identifiers are assigned in blocks to the organisations that request them, so consecutive numbers from one vendor mean the vendor reserved them together, not that the bugs share a cause.

It is an easy inference to draw and it would be wrong, which matters in a week when both numbers are circulating in the same advisories.

What to patch

The fixed releases are specific. ISE 3.1 needs Patch 12, 3.2 needs Patch 11, 3.3 needs Patch 12, 3.4 needs Patch 7 and 3.51 needs Patch 4. Anything earlier in each train remains exposed.

Cisco disclosed a cluster of further critical ISE flaws at the same time, including one more scored at 10.0 and others in the nines. The patch for this one covers those as well, which argues for treating the whole set as a single emergency rather than triaging within it.

Anyone patching should also assume the window mattered. An authentication bypass on a policy engine is the kind of access that gets used to establish something more durable, and the advisory gives no date for when exploitation began.

Advertisement

What to watch

Federal civilian agencies have until 19 September under the KEV listing, and that date is a useful public marker for everyone else. The deadline is short, which is CISA's assessment of how quickly this one matters.

Attribution is still open. Nobody has named an actor. Network access control appliances are a standing target for both espionage operations and ransomware crews, and the absence of attribution in the first week means nothing either way; it usually arrives later, from whoever gets to do the incident response. Our earlier reporting on the Firepower Management Center flaw showed how long that takes and how mixed the answer can be.

The catalogue pattern fits. This is another entry in a month where KEV additions have been arriving in clusters, and the common shape is not a novel technique. It is an appliance at the edge of the network, running an interface that should never have been reachable in the way it was.

Advertisement
Kenji Tanaka
Developer Tools & Cloud Analyst

Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement