Cisco has patched a maximum-severity flaw in Identity Services Engine (ISE) that attackers were already exploiting before a fix existed. The Cisco ISE vulnerability, tracked as CVE-2026-76460, scores a full 10.0 on the CVSS scale and lets an unauthenticated, remote attacker bypass authentication entirely. Cisco’s own advisory puts the cause plainly: insufficient authentication control on an API endpoint, which is a different failure mode from a weak check, since there is no check to weaken in the first place.
What the ISE vulnerability actually lets an attacker do
ISE is Cisco’s network access control engine: it decides which devices and users get onto a network, and under what policy, using RADIUS and 802.1X. An API endpoint that skips authentication on a platform like that is not a minor information leak, it is a door into the system that grants or denies network access in the first place. An unauthenticated attacker who reaches that endpoint does not need to steal a credential or phish an admin, they just need network reachability to the API. That is why Cisco and the CVSS scoring both treat this as a full 10.0 rather than a high-but-not-critical bypass.
Cisco’s second zero-day in three days
This is the second Cisco zero-day teqpost has covered this month. On 15 September we reported on a Secure Email Gateway zero-day that was exploited before a patch existed. That flaw sat in a different product and did not carry a perfect CVSS score. This one does, and it hit three days later, on the same underlying pattern: exploitation in the wild predates the fix, meaning any ISE deployment exposed to the internet or an untrusted segment before the patch shipped should be treated as potentially already compromised.
By our arithmetic, The Hacker News and BleepingComputer published their reports within 41 minutes of each other. That gap is too tight for one outlet to have found the flaw independently and the other to have caught up through separate reporting. It points to a coordinated disclosure: Cisco briefed press ahead of a fixed publication window, rather than reporters racing each other to a scoop. Worth knowing before treating either write-up as an independent confirmation of severity, since both are downstream of the same vendor timeline.
What to watch
Cisco has already shipped the fix, so the immediate action for anyone running ISE is patching, not waiting for more detail. What is still open is scope: Cisco’s advisory will likely be updated with the affected version list and indicators of compromise as its investigation continues, and that update is worth checking against any ISE instance that was internet-facing or exposed to an untrusted VLAN before the patch landed.








