Cisco warns a maximum-severity Identity Services Engine zero-day is under active exploitation
CVE-2026-76460 lets remote attackers bypass authentication on an API endpoint regardless of configuration, and the only mitigation is upgrading.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
Cisco has released security updates for a maximum-severity vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that attackers are actively exploiting. Tracked as CVE-2026-76460, the flaw stems from insufficient authentication control on an API endpoint. A remote attacker can send a crafted request to that endpoint and gain unauthorized access to the device by bypassing the web-based management interface. The weakness applies regardless of configuration. ISE is a centralized policy platform that administrators use to manage endpoint, user and device access to network resources, often as the enforcement point for Zero Trust designs. A compromised ISE deployment therefore affects access decisions across the network rather than a single appliance. Cisco's Product Security Incident Response Team said on Wednesday that it is aware of active exploitation and 'strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.' No workarounds exist, so applying the security updates is the only recommended course of action. The advisory follows Cisco's recent disclosure of a separately exploited Secure Email Gateway zero-day, CVE-2026-76461, that gives root through a crafted email. Organizations running both products now have two actively exploited Cisco zero-days to patch in short succession, and administrators should treat the ISE update as urgent given that the flaw needs no user interaction and cannot be mitigated by configuration.
Sources
- BleepingComputerCisco warns of max severity ISE zero-day exploited in attacks