CVE 2026 76460, the unauthenticated bypass in Cisco Identity Services Engine, is rated the maximum severity, is under active attack, and carries a CISA patch deadline of September 19.
Cisco disclosed CVE-2026-76460 on September 17, a CVSS 10.0 unauthenticated remote authentication bypass in its Identity Services Engine and ISE-PIC products. The flaw was already being exploited when Cisco's own engineers surfaced it while resolving a Technical Assistance Center support case, the vendor advisory says.
The bug sits in insufficient authentication on an API endpoint. A successful exploit lets an unauthenticated attacker bypass the web management interface and may lead to root-level command execution on the ISE host. Cisco has not disclosed the threat actor, attack duration, or post-exploitation behavior, The Register reports.
Patched versions are ISE and ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. ISE 3.0 is out of maintenance, so customers on that branch must migrate. There is no workaround; Cisco lists infrastructure access-control lists as the only mitigation for organizations that cannot patch immediately.
CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 16 and set a September 19 patch deadline for Federal Civilian Executive Branch agencies, The Hacker News reports.
For detection, Cisco points operators at the ise-kong/access.log file, advising teams to look for unusual usernames. The vulnerability shipped inside Cisco's 77-CVE September bundle, which also includes a separate actively exploited flaw in Secure Email Gateway tracked as CVE-2026-76461.