A critical vulnerability (CVSS 10) in the Cisco Identity Services Engine (ISE) is being exploited in the wild – and gives a remote, unauthenticated attacker command execution with root privileges on the device.
The vulnerability has been allocated CVE-2026-76460 and was found by Cisco whilst conducting technical support for a customer – it affects all supported versions, irrespective of configuration, Cisco warned today.
Exploitation of the vulnerability represents a colossal headache for Blue Teams: It gives attackers deep access to Cisco’s enterprise Network Access Control (NAC) and policy management platform – which handles authentication and authorisation across every kind of network.
Those with strict infrastructure access control lists (iACLs) will have already mitigated most of the risk of remote exploitation by opportunists, but may want to patch fast regardless given the severity and ongoing attacks. (It was not immediately clear how widespread exploitation was.)
"Insufficient authentication control" - again?
Cisco shared some basic IOCs in a September 16 advisory and said if "malicious activity is suspected, it is strongly recommended to re-image the affected nodes and restore from configuration backup if needed."
Cisco also warned that:
"Because of this level of access [root], evidence of exploitation and indicators of compromise may be removed or hidden by the threat actors. Cisco strongly recommends that administrators cross-check the network logs and the firewall logs outside of the impacted device to identify any potential suspicious activity, including but not limited to unexpected uploads that were initiated from the affected device to external IP addresses or downloads from malicious IP addresses."
The nature of the vulnerability may infuriate customers: Cisco described it as due to “insufficient authentication control on an API endpoint.”
That means it represents the latest in a lengthy history of authentication bypass-related and other trivial vulnerabilities found in Cisco products.
The company has regularly been guilty over the years of shipping products with hard-coded passwords in them; they keep getting found.
(As recently as July this year a bug in Cisco’s “Secure Firewall Management Center” was added to CISA’s “Known Exploited Catalog” KEV. The cause of the flaw? Static user credentials, again.)
Just earlier this very week (September 14) meanwhile a SQL injection vulnerability in the “Cisco Secure Email Gateway” was added to KEV.
(Along with hard-coded creds, SQLi bugs represent the most low-hanging fruit/most egregious “Do Not Allow This Thing” product weaknesses and checks for them are regularly flagged in any Secure by Design initiative.)
Product security teams may have some sympathy: LLMs are making it easier than ever to spot previously unseen vulnerabilities and develop exploit chains for them. But the companies selling enterprise network security software to some of the world’s biggest organisations have the same tools as threat actors, and better access to internal IP that can help them assess and reinforce product security. They need to do better.
Notably, CISA has already added 17 Cisco vulnerabilities to KEV this year. That’s up sharpy from nine in 2025 and six in 2024.
Other known-exploited Cisco bugs this year include CVE-2026-20131 – which AWS found had been exploited as zero day by a ransomware group since January – 36 days before it was publicly disclosed.
“See everything. Control what happens next” boasts Cisco of ISE.
That’s a capability bad actors may now have.
Patch up and threat hunt.
Get a The Stack/Runtime newsletter sponsorship slot like this - and your capabilities in front of 30,000+ subscribers and 1m web users.