Cisco has confirmed active exploitation of a maximum-severity vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products, tracked as CVE-2026-76460 and rated a perfect 10.0 on the Common Vulnerability Scoring System scale. The flaw stems from insufficient authentication controls on an API endpoint.
An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint.
Successful exploitation could grant attackers root-level command execution and unauthorized device access without any valid credentials.
Who needs to act
ISE and ISE-PIC are used by organizations — not typically individual consumers — to control network access and enforce identity policies. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog on September 16, 2026, giving federal civilian agencies until September 19 to patch. Private organizations running ISE face the same active-exploitation risk on the same timeline, even without a legal mandate.




