Cisco ISE zero-day exploited, CVSS 10.0 auth bypass
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
What Happened
Cisco has disclosed and patched a maximum-severity authentication bypass in Identity Services Engine (ISE), tracked as CVE-2026-76460. The vulnerability carries a CVSS score of 10.0 and is confirmed exploited in the wild. Cisco released fixed software versions alongside the advisory, but exploitation was already underway before the patch became available, making this a true zero-day. ISE is the policy decision point for enterprise network access control, so the flaw sits at the center of zero-trust segmentation for many large organizations.
Why It Matters
ISE authenticates and authorizes users and devices across wired, wireless, and VPN infrastructure. A 10.0 auth bypass means an unauthenticated attacker can impersonate trusted identities or bypass policy enforcement entirely, potentially gaining a foothold on restricted network segments without valid credentials. Because ISE integrates with Active Directory and acts as a RADIUS/TACACS+ authority, compromise can ripple into VPN access, 802.1X admission, and device posture decisions. This follows a steady drumbeat of Cisco edge exploitation - including the Secure Email Gateway RCE (CVE-2026-76461) and the ASA/FTD VPN denial-of-service (CVE-2026-20349) - suggesting attackers are systematically targeting Cisco security infrastructure.
Technical Details
The bypass allows a remote, unauthenticated attacker to circumvent ISE authentication controls under specific deployment configurations. Cisco’s advisory does not publish a public proof-of-concept, but active exploitation indicates attackers have working access. Affected systems include ISE deployments across common release trains; administrators should verify their version against Cisco’s fixed-software matrix. Treat any ISE node reachable from untrusted networks as exposed until patched. Indicators of compromise center on anomalous authentication events, unexpected administrative logins, and policy changes logged in ISE’s audit trail.
Immediate Risk
Given the 10.0 rating, active exploitation, and the privilege ISE holds, the operational risk is severe. Organizations using ISE for network admission control should treat patching as emergency maintenance, not routine change management. Where patching cannot happen immediately, isolate administrative interfaces behind strict allowlists and monitor ISE audit logs for policy modifications and device re-authentication bursts. Note that identity-infrastructure compromise often precedes ransomware staging - the recent University of San Francisco ransomware claim is a reminder that access brokers monetize exactly this kind of foothold.
Security Insight
The instinct is to patch and move on, but ISE is a policy brain, not just an endpoint - a single compromised node can silently rewrite who is trusted network-wide. Unlike a perimeter firewall breach, which tends to generate noisy deny logs, an ISE compromise may look like legitimate policy enforcement, granting attackers quiet, durable access that survives password resets. Security teams should therefore pair the patch with a forensic review of recent policy and identity changes, treating this as a potential trust-anchor compromise rather than a simple gateway bug.
Further Reading
Never miss a security update
Get real-time security alerts delivered to your preferred platform.
Related News
Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [.
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorize
Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileges. [...]