AIO APEX

Cisco patches max-severity ISE zero-day already under active attack

BleepingComputer
Share:
Cisco patches max-severity ISE zero-day already under active attack

Cisco disclosed and patched a maximum-severity authentication bypass vulnerability in its Identity Services Engine on Wednesday, warning that attackers are already exploiting the flaw in the wild. The US Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog the same day, giving federal civilian agencies until September 19 — three days — to patch under Binding Operational Directive 26-04.

What the Flaw Actually Does

Tracked as CVE-2026-76460 and carrying a perfect CVSS score of 10.0, the vulnerability stems from insufficient authentication control on an API endpoint in Cisco ISE and its Passive Identity Connector variant. A remote, unauthenticated attacker can send a specially crafted request to that endpoint and bypass the web-based management interface entirely — no valid credentials required. Cisco confirmed that successful exploitation can escalate to command execution with root privileges, which would let an attacker not just access the system but erase or alter logs to hide evidence of the intrusion afterward.

The flaw affects Cisco ISE and ISE-PIC releases 3.0 through 3.5 regardless of how the device is configured — there is no configuration workaround that avoids exposure, which is unusual and makes patching the only real mitigation. Fixed versions are available: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4.

Why Identity Services Engine Is a High-Value Target

ISE is Cisco's network access control platform — it sits at the point where devices authenticate onto a corporate network, making decisions about who and what gets access to which network segments. A platform that authenticates every device on a network is, by definition, a single point that grants broad reach if compromised: an attacker who bypasses ISE's own authentication doesn't just gain a foothold, they gain a vantage point that controls access decisions for the rest of the network. Cisco has recommended organizations review access.log files for suspicious usernames and cross-check network and firewall logs for signs the flaw has already been exploited against them.

The Broader Pattern

This is at least the third maximum-or-near-maximum-severity Cisco networking flaw added to CISA's KEV catalog in the past two months, following a Firepower Management Center vulnerability exploited by the Sandworm APT group in September and a WatchGuard flaw tied to ransomware campaigns earlier the same month. Enterprise network infrastructure vendors — the boxes that sit at the perimeter or control access decisions rather than the endpoints behind them — have become a preferred target precisely because compromising one device of this kind can grant visibility or control over everything connected to it, a return on effort that individual endpoint compromises rarely match.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share: