Particle.news

Cisco Issues Emergency Patch for Maximum‑Severity ISE Zero‑Day

The U.S. added the flaw to its Known Exploited Vulnerabilities list with a three‑day federal patch deadline to force rapid remedial action.

Overview

  • Cisco disclosed and released fixes for CVE-2026-76460 after the company found the authentication‑bypass was being exploited in the wild, a situation the vendor flagged on Wednesday.
  • The flaw is an insufficient‑authentication bug in an ISE API that lets an unauthenticated remote attacker bypass the web management interface, obtain administrative or root command execution, and remove forensic evidence.
  • Cisco published indicators of compromise and fixed builds for ISE and ISE‑PIC — customers should upgrade to the listed patch releases because no reliable workaround exists.
  • CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and gave federal civilian agencies a three‑day remediation window that requires patching or mitigation by September 19, 2026.
  • Security responders are urged to restrict management‑plane access with infrastructure ACLs, hunt external logs for suspicious API activity, rotate credentials and re‑image affected nodes if compromise is suspected because patching alone may not remove attacker persistence.