Skip to content
Some links are advertising or affiliate links. How we make money
THRYV News

Independent reviews, guides and reporting.

Software & CRM

News

Cisco Warns of a Maximum-Severity Flaw Being Actively Exploited Right Now

A newly disclosed authentication bypass in Cisco's Identity Services Engine scores a perfect 10.0 on the CVSS scale and is already under attack.

By THRYV Money Desk·Published September 18, 2026·Updated September 18, 2026·4 min read
Cisco Warns of a Maximum-Severity Flaw Being Actively Exploited Right Now
Software & CRM · Illustration commissioned for THRYV. Photography is replaced with original imagery as each story is produced.

The takeaway

Cisco disclosed an actively exploited, maximum-severity flaw (CVE-2026-76460, CVSS 10.0) in its Identity Services Engine and ISE-PIC products that lets unauthenticated attackers bypass login and gain root-level access. CISA added it to its Known Exploited Vulnerabilities catalog on September 16 with a September 19 patch deadline for federal agencies. Patches are available now.

Cisco has confirmed active exploitation of a maximum-severity vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products, tracked as CVE-2026-76460 and rated a perfect 10.0 on the Common Vulnerability Scoring System scale. The flaw stems from insufficient authentication controls on an API endpoint.

An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint.
Cisco security advisory

Successful exploitation could grant attackers root-level command execution and unauthorized device access without any valid credentials.

Who needs to act

ISE and ISE-PIC are used by organizations — not typically individual consumers — to control network access and enforce identity policies. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog on September 16, 2026, giving federal civilian agencies until September 19 to patch. Private organizations running ISE face the same active-exploitation risk on the same timeline, even without a legal mandate.

Which versions are affected and fixed

  • ISE 3.1: fixed in Patch 12
  • ISE 3.2: fixed in Patch 11
  • ISE 3.3: fixed in Patch 12
  • ISE 3.4: fixed in Patch 7
  • ISE 3.51: fixed in Patch 4

What administrators should do

Cisco and security researchers recommend upgrading to the patched version immediately, reviewing access logs for suspicious usernames using Cisco's published detection commands, and re-imaging any node found to be compromised. Organizations that can't patch immediately are advised to restrict management-interface traffic using infrastructure access control lists.

Why it's rated a perfect 10

A CVSS score of 10.0 is the maximum possible severity rating, reserved for flaws that are both trivial to exploit remotely and capable of full system compromise with no authentication required.

Sources

This article is original writing by THRYV. We link to primary reporting and official documents rather than reproducing them.

  1. Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active AttacksThe Hacker News
  2. Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-DaySecurityWeek

Why you can trust this article

Written and edited in-house by the THRYV Money Desk. We do not republish or reword agency copy, and we do not invent quotes, statistics, testimonials or ratings. Where figures move frequently, we point you to the primary release rather than printing a number that will be out of date. Advertising and affiliate partnerships have no influence on our reporting — see our editorial standards, fact-checking policy and affiliate disclosure. Spotted an error? Write to newsroom@thryv-news.com.

General information only. Not personalised financial, medical or legal advice.

Related reading

The THRYV Brief

The market in 5 minutes, weekday mornings

Plain-English analysis, the sources behind it, and what it changes for you. Free, and you can unsubscribe any time.

Free. Unsubscribe any time. We never sell your email address.

Advertisement · Newsletter sponsorship600×120
Advertise with THRYV News — medium rectangle placement available

This position is available to a single sponsor per edition, is labelled in the email and on this page, and does not influence what the Brief covers.

Advertisement
Advertise with THRYV News — medium rectangle placement available