Another Day, Another Zero-Day
Well, Cisco’s at it again, folks. Administrators who just updated their email gateways are now faced with another hefty 10 out of 10 vulnerability to tackle, this time in the Identity Services Engine (ISE). This gem of a flaw, CVE-2026-76460, was revealed on Wednesday, and it’s a significant one.
What’s the Scoop?
This vulnerability presents a risky authentication bypass that allows any rogue individual to achieve remote command execution with root privileges on your ISE and ISE Passive Identity Connector (ISE-PIC). The Product Security Incident Response Team has alerted that this flaw is actively being exploited, so you better implement those fixes quickly. Even the top brass at CISA have added it to their Known Exploited Vulnerabilities catalog.
A Tale of Two Vulnerabilities
Patch and Panic
This one comes right after another blunder, CVE-2026-76461, which has been giving Cisco’s Secure Email Gateway and Web Manager appliances a tough time. That one scored a 9.8, nearly hitting the top of the scale and had people anxious about root access as well. Attackers were possibly covering their tracks, much like when your dog swipes a sausage roll and pretends to be innocent.
The Details: API Antics
No Credentials, No Issue
The trouble with CVE-2026-76460 stems from inadequate authentication controls on an API endpoint. In straightforward terms, a crafty attacker can send a specially crafted request to bypass the web-based management interface without any credentials or user interaction required. All vulnerable versions of ISE and ISE-PIC are impacted, no matter how you have it configured.
Root Access: An Open Invitation
The flaw received the maximum CVSS score of 10.0. Cisco cautions that this kind of root access means attackers could erase or conceal signs of intrusion, making it quite challenging to determine if your equipment has been compromised. They’re recommending administrators keep a close watch on ISE access logs for any suspicious usernames and to scrutinize network and firewall logs for any unusual activities.
Mitigation and Solutions
No Quick Fix Here
There’s no workaround available for this one, but Cisco suggests utilizing infrastructure access control lists as a temporary measure to safeguard the management and control-plane traffic. Permanent solutions are included in the latest ISE and ISE-PIC patches, so make sure to apply them if you haven’t yet.
End of the Road for ISE 3.0
For those still holding on to ISE 3.0, it’s hit the end of its software maintenance, so you’d be wise to upgrade to a supported release quickly. Cisco discovered CVE-2026-76460 while addressing a Technical Assistance Center support case, but they’re remaining tight-lipped about who’s exploiting it, how long it’s been happening, or what damage might have occurred.
Summary: “Patch, Pray, Repeat”
For the administrators managing Cisco equipment, September is shaping up to be an intense patching marathon. So, stay alert and perhaps cut back on the coffee – it’s going to be a long month.