Cisco's Maximum-Severity ISE Flaw Gets a 3-Day Deadline
Security / news
Cisco's Maximum-Severity ISE Flaw Gets a 3-Day Deadline
CISA gave federal agencies until Sept. 19 to patch CVE-2026-76460, a root-access bypass Cisco found while resolving a support case, not during a planned review.

An unauthenticated remote attacker who can reach the management API of Cisco's Identity Services Engine can bypass its authentication controls entirely and obtain root access to the appliance, with no valid credentials and no user interaction required. Cisco confirmed active exploitation of the Cisco ISE vulnerability, tracked as CVE-2026-76460, when it shipped fixes Sept. 16, and the Cybersecurity and Infrastructure Security Agency gave federal civilian agencies until Sept. 19 to patch it under Binding Operational Directive 26-04.
ISE is the appliance that decides which devices get onto a network in the first place, which is what makes root access on it consequential rather than merely embarrassing. "ISE devices enforce network access policy, so root access on the appliance lets an attacker modify that policy, extract stored credentials, delete logs, and move laterally into every network segment ISE controls," said Landon Rice, senior exploit developer at security firm VulnCheck, in comments reported by CyberScoop.
What the Cisco ISE vulnerability lets an attacker do
Cisco's own advisory describes the root cause as insufficient authentication control on an API endpoint, discovered, Cisco said, while its team resolved a Technical Assistance Center support case rather than during a scheduled audit. The company says there are no workarounds; the fix requires upgrading to a patched release. The score does not overstate the risk here: a 10.0 rating for an unauthenticated attacker who ends up with root is the correct read, not an inflated one.
| ISE release | First fixed version |
|---|---|
| 3.1 | Patch 12 |
| 3.2 | Patch 11 |
| 3.3 | Patch 12 |
| 3.4 | Patch 7 |
| 3.5 | Patch 4 |
A second Cisco zero-day in two days
CVE-2026-76460 is the second maximum-severity Cisco flaw disclosed in a two-day span. On Sept. 15, Cisco patched CVE-2026-76461, a CVSS 9.8 flaw in Secure Email Gateway that let an unauthenticated attacker execute commands as root by sending a specially crafted email, also discovered during a support case and also under active exploitation before the patch shipped. CISA added that CVE to its Known Exploited Vulnerabilities catalog with a Sept. 17 deadline, two days before the ISE deadline landed. Neither advisory names the attacker or says how many organizations were compromised before the fixes shipped, unlike the extortion campaigns The Terminal has covered this month, such as ShinyHunters' hijacking of Cl0p's dark-web leak site, where the group behind an intrusion identified itself.
The compressed timeline matches a pattern The Terminal has tracked elsewhere this month: CISA gave agencies three days to patch a Zyxel switch flaw after adding it to the KEV catalog, the same interval it set here. What is different is the product category. A switch flaw affects the switches it runs on; an ISE flaw affects every device the switches, routers and wireless access points downstream of it were trusting ISE to vet.
What Cisco has not said
Cisco has not said how it identified the exploitation, whether it was reported by the customer whose support case surfaced the bug or found independently, and has not disclosed how many ISE deployments were compromised before Sept. 16. It has also not said whether CVE-2026-76460 and CVE-2026-76461 share a common origin or were found and exploited separately, a question that matters for anyone trying to judge whether one attacker or several are behind the pair.
Sources
More in Security
- 01CISA Gives Agencies 3 Days to Patch an Exploited SharePoint BugMicrosoft rated the flaw a low-risk spoofing issue for 16 days after patching it, and a honeypot logged the first attack four weeks after the correction upgraded it to an 8.8.
- 02CISA Adds a Fourth MikroTrick Bug to Its Exploited ListCVE-2026-67279 joins two other bugs from the same six-flaw MikroTik batch already on CISA's list, but Bishop Fox says it, not the pair flagged in September, is the one that actually opens the door.
- 03OpenClaw's New Scanners Agree on Just 0.69% of Risky SkillsFour audits since February have counted between 341 and 1,467 malicious or flawed skills on ClawHub, and NVIDIA's scanner disagrees with the other two on all but 468 of 67,453 skills checked.
- 04CISA Lists 14 Botslab Dashcam Flaws With No Fix in SightThe worst of the bugs lets a network attacker push firmware with no cryptographic signature onto the device, and Botslab has not told CISA whether it plans to fix any of the 14.