Particle.news

Cisco Issues Emergency Patches for Actively Exploited ISE Zero‑Day

It lets unauthenticated attackers gain root control of network access appliances, raising the risk of policy manipulation, credential theft, deletion of forensic logs.

Overview

  • CVE-2026-76460 is a maximum-severity (CVSS 10.0) authentication‑bypass bug in Cisco Identity Services Engine and ISE Passive Identity Connector that attackers are actively exploiting to take control without logging in.
  • Cisco released emergency fixes for supported 3.x ISE and ISE‑PIC branches and published indicators of compromise to help customers hunt for signs of intrusion.
  • There are no practical workarounds for the flaw so organizations are urged to patch immediately and to review access.log files and external network and firewall logs for unexpected usernames or transfers.
  • The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal civilian agencies to remediate or mitigate by September 19, 2026.
  • Because ISE enforces network access policies, successful compromises can let attackers change access rules, steal credentials, erase local logs, and move laterally, so affected nodes may need re‑imaging and broad forensic correlation to restore trust.