Exploited Cisco ISE zero-day scores a perfect ten and hands attackers root
Cisco warned that attackers are exploiting a critical zero-day in its Identity Services Engine, the platform that decides which devices are allowed onto a network. Tracked as CVE-2026-76460 and scored 10.0, the flaw is an authentication bypass caused by insufficient authentication controls on an API endpoint, so an unauthenticated attacker can send a crafted request, bypass the management interface, and ultimately gain root. It affects ISE and its Passive Identity Connector regardless of configuration, with no workaround beyond restricting network access. Because a rooted appliance sitting at the network's front door can be used to erase evidence, Cisco urges checking external logs. CISA set a three-day federal patch deadline.
- Check
- Patch Cisco ISE and its Passive Identity Connector to a fixed release immediately, since there is no workaround and exploitation is active, and restrict who can reach the appliance until patched.
- Affected
- Organizations running Cisco ISE or ISE Passive Identity Connector in any configuration (CVE-2026-76460); an unauthenticated attacker can bypass authentication through an API endpoint and gain root, exploitation confirmed in the wild.
- Fix
- Patch now, restrict access with infrastructure access lists, cross-check external network and firewall logs since a rooted device can hide its own indicators, and treat any exposed unpatched ISE as likely compromised.