Cisco's Network Gatekeeper Has a Perfect-10 Flaw and Hackers Are Already Inside

A zero-day in Cisco Identity Services Engine lets anyone on the internet walk past the login screen entirely. Federal agencies have three days to patch. There is no workaround.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • CVE-2026-76460 carries a perfect CVSS score of 10 out of 10 and is confirmed as actively exploited in the wild.
  • The flaw affects Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), software that acts as a digital gatekeeper controlling who can log into corporate and government networks.
  • Cisco confirmed that attackers who successfully exploit the flaw can run commands with the highest possible system privileges, then erase the evidence.
  • CISA added the flaw to its Known Exploited Vulnerabilities catalogue under BOD 26-04, ordering US federal agencies to patch within three days of listing.
  • Five patched software versions are available; Cisco states there are no workarounds that fully address the vulnerability.

Cisco Identity Services Engine is essentially the bouncer for corporate and government networks. It checks whether a device or user is allowed in before granting access to anything else. When it breaks, everything behind it is exposed.

That's what happened here. CVE-2026-76460 sits in an application programming interface (API), a channel that lets software systems talk to each other. Because that channel lacks proper authentication checks, a criminal anywhere on the internet can send it a specially crafted request and skip the login process entirely. No credentials. Full access to the management interface.

Cisco's own advisory makes the consequence plain: a successful attack can grant root privileges, the highest level of control over a machine. With root access, an attacker can install software, scrub the audit logs that would normally reveal the intrusion, and leave incident responders with almost nothing to work with. Both ISE and ISE-PIC are affected regardless of configuration.

We covered a similar situation on 9 September, when a perfect-score bug in Cisco's Secure Firewall Management Center was found to have been exploited weeks before Cisco confirmed it publicly. The pattern is holding.

How do affected organisations know if they have already been hit?

They may not. Attackers with root access can scrub logs on the compromised device itself. Cisco advises teams to cross-check firewall logs and network flow data held outside the affected machine. On the device, administrators should search the access.log file for usernames that shouldn't be there. If suspicious activity turns up, Cisco's recommendation is to wipe the affected node entirely and restore from a clean backup, not just patch over it.

What needs to be patched, and how fast?

Patches are out now. Cisco says organisations should upgrade to one of five fixed releases.

Software Fixed version
ISE / ISE-PIC 3.5 Patch 4
ISE / ISE-PIC 3.4 Patch 7
ISE / ISE-PIC 3.3 Patch 12
ISE / ISE-PIC 3.2 Patch 11
ISE / ISE-PIC 3.1 Patch 12

US federal agencies face a hard three-day deadline under the standing BOD 26-04 directive, which requires agencies to fix known-exploited vulnerabilities on an emergency timeline. That window is unusually short and reflects how seriously CISA views active exploitation.

For organisations that can't patch immediately, restricting which IP addresses can reach the ISE management interface via infrastructure access control lists limits remote exposure. Cisco's clear that this is mitigation only.

Cisco hasn't said publicly who is behind the active attacks or which sectors have been targeted. Its products are widely deployed across government, finance, healthcare and critical infrastructure. SecurityWeek first reported Cisco's public confirmation of active exploitation.

The honest read: a CVSS 10 with confirmed in-the-wild exploitation and a three-day federal patch window isn't a drill. Organisations running ISE that are waiting for a scheduled maintenance window should reconsider that plan today.

© 2026 Threat Vectr