• Sources: primary, CISA KEV catalog, coverage
  • Summary: The Cisco advisory covers CVE-2026-76460, an authentication bypass in Identity Services Engine and the ISE Passive Identity Connector rated 10.0 that yields unauthenticated remote root, with fixes in ISE and ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4, and ISE 3.0 past end of software maintenance and requiring migration instead. Cisco states that no workaround exists and names infrastructure access control lists as a temporary mitigation that restricts management and control-plane traffic reaching affected systems. The CISA known exploited vulnerabilities catalog carries it with a remediation deadline of 2026-09-19, and The Register covers it as another actively exploited Cisco zero-day.
  • Why it matters: Unauthenticated remote root on a network access control platform is being exploited now, and the access control list mitigation only buys time for a deployment that cannot reach a fixed patch level before 2026-09-19.
  • Follow-up: Track attacker attribution, dwell time, and an affected-deployment count, none of which Cisco has disclosed.

send feedback on this story