Cisco has patched a critical security vulnerability in the Identity Services Engine (ISE) that is already being actively exploited. Attackers can gain root privileges without credentials. The vulnerability has been assigned a maximum score of 10.0 on the CVSS scale.
The vulnerability, CVE-2026-76460, is located in an API endpoint used for managing ISE, reports NetworkWorld. By sending specially crafted requests, an attacker can bypass the normal authentication process via the web interface and gain full control over the system.
Cisco ISE is deployed within corporate networks to determine which users and devices are granted access to network resources. Cisco ISE Passive Identity Connector (ISE-PIC) is also vulnerable. The vulnerability exists regardless of the configuration of either product.
Cisco has released patches for the various supported versions. These include ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4.
Exploitation confirmed
The fact that this is not merely a theoretical risk is evident from the addition of CVE-2026-76460 to the “Known Exploited Vulnerabilities” catalog of the U.S. Cybersecurity and Infrastructure Security Agency (CISA). This confirms that attackers are actively exploiting the vulnerability.
Administrators are advised to check the access.log of ISE systems for suspicious usernames. However, this check does not provide certainty. Because a successful attacker gains root privileges, they can also delete log files. Cisco therefore recommends also examining network and firewall logs for unusual traffic to and from the affected systems.
If there are indications that a system has actually been compromised, Cisco recommends reinstalling the affected node. The configuration can then be restored from a backup if necessary. Infrastructure access control lists (iACLs) can also be used to further restrict management and control traffic to ISE systems.
Many more vulnerabilities found
The vulnerability came to light during a broader review of ISE and ISE-PIC. Cisco has addressed a total of 21 critical vulnerabilities as a result. These include several remote code execution vulnerabilities and API leaks in the same category as CVE-2026-76460. In addition, three vulnerabilities with a high severity rating and eighteen with a medium severity rating were addressed.
Other Cisco security products also received patches this week. The company addressed vulnerabilities in products including the Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center.
CVE-2026-76460 is Cisco’s second critical zero-day vulnerability in just a few days. Earlier this week, the company released an emergency patch for an actively exploited vulnerability in Secure Email Gateway. That vulnerability also allowed attackers to gain root access to affected systems.