Cyber & Resilience - 6 min read - 22 September 2026

Cisco patched a perfect 10 in its identity platform. Two days earlier, it had patched a different zero-day already under attack.

On 16 September, Cisco shipped an emergency fix for CVE-2026-76460, a maximum-severity authentication bypass in Identity Services Engine that attackers were already exploiting before the patch existed. It was the second unrelated zero-day Cisco had been forced to fix that week, after an actively exploited flaw in its Secure Email Gateway two days earlier. Cisco says the consecutive CVE numbers are a coincidence of assignment order, not a shared root cause - which is arguably the less comfortable explanation, since it means two separate teams found two separate ways in during the same seven days.

CVE-2026-76460 sits in an API endpoint on Cisco ISE and ISE Passive Identity Connector, and it doesn't care how the appliance is configured. BleepingComputer's report quotes Cisco's own advisory on the mechanics: "An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint." No credentials, no user interaction, no workaround Cisco is willing to recommend - the fix is the patch, applied across releases 3.1 through 3.5, or nothing. Cisco's Product Security Incident Response Team confirmed exploitation in the wild before the advisory went out, and CISA added the CVE to its Known Exploited Vulnerabilities catalog the same day, giving federal civilian agencies three days - until 19 September - to patch.

What root on an ISE box actually buys an attacker

It's worth being specific about why this particular product matters more than its category suggests. ISE isn't a file server or a marketing tool - it's the box that decides which devices and users get onto the network in the first place. Landon Rice, a researcher at VulnCheck, put it plainly in CyberScoop's coverage: "ISE devices enforce network access policy, so root access on the appliance lets an attacker modify that policy, extract stored credentials, delete logs" and move laterally into every segment ISE controls. An authentication bypass here isn't a foothold you build on - it's closer to handing over the building's access-control system along with the key to erase the visitor log afterward.

Two zero-days, unrelated, seven days apart

CVE-2026-76460 landed two days after Cisco patched CVE-2026-76461, an unrelated actively-exploited flaw in Secure Email Gateway. The near-consecutive CVE numbers invited an obvious question, and CyberScoop put it to Cisco directly. The answer was almost anticlimactic: "CVEs are assigned on a first-come, first-served basis, so consecutive numbering reflects assignment order rather than any relationship between the issues," a spokesperson said. That's a correct technical answer and a slightly unsettling one - it means the numbering is coincidence, but the underlying fact isn't: two independent security failures, in two independent products, both already being exploited, surfaced in the same week from the same vendor.

ISE has been a live target for over a year

This also isn't ISE's first appearance on the exploited list. CyberScoop's reporting notes active exploitation of ISE vulnerabilities going back to June 2025, including CVE-2025-20337 and CVE-2025-20281, both rated critical. Three critical, actively-exploited ISE bugs in fifteen months is a pattern, not a run of bad luck, and it argues for treating the platform itself - not just this one CVE - as a standing priority in any environment where it sits in front of network access decisions.

  • Patch every Cisco ISE and ISE-PIC instance to the fixed release for its branch (3.1-3.5) immediately - there is no supported workaround for CVE-2026-76460.
  • Pull the indicators of compromise Cisco published alongside the advisory and run them against ISE logs now, not after the next scheduled review.
  • Because root access lets an attacker delete logs on the way out, don't rely solely on ISE's own audit trail to rule out prior compromise - cross-check against network access records from downstream switches and firewalls.
  • If your ISE deployment has been exploited via any of the three critical bugs disclosed since June 2025, treat it as a standing high-value target and review its patch cadence separately from your general appliance fleet.
  • Don't let "the CVE numbers are unrelated" read as "the risk is unrelated" - two unrelated exploited zero-days from one vendor in a week still means two incident response tracks running at once.

A perfect-10 CVSS score on the box that decides who gets network access is about as clear a priority signal as security tooling ever produces. If you'd like help auditing how exposed your identity and access infrastructure is to exploited-in-the-wild flaws like this one, email sales@halfteck.com.

Explore more resources

Browse our full library of enterprise cloud, software, data and AI content.

View all resources