Vulnerability Management, Patch/Configuration Management

Cisco patches 10.0 ISE bug exploited in the wild

Cisco Logo on a Modern Office Building

Cisco on Sept. 16 patched a maximum-severity authentication bypass vulnerability in the API of Cisco Identity Services Engine (ISE) that the networking vendor said was actively exploited in the wild.

Because of the active exploitation, the Cybersecurity and Infrastructure Security Agency (CISA) also put CVE-2026-76460 on its known exploited vulnerabilities (KEV) list.

According to Cisco, a successful exploit could let an attacker gain unauthorized access to an ISE device by bypassing the web-based management interface.

For many years, Cisco ISE has been one of the leading network access control platforms used by enterprises to centrally-manage security policies, verify user and device identities, and control access across enterprise networks.

Concerned more about long-term lateral movement than an initial exposure, security pros said teams should make CVE-2026-76460 the top item on their patching queue.

“This isn't just another vulnerability,” said Robert Coles, senior manager of threat intelligence security at Black Duck. “It's a potential gateway to broader compromise. That’s why organizations should patch quickly and look for signs that attackers have already been inside.”

John Strand, owner at Black Hills Information Security, said teams should patch right away and take ISE off the open internet. Strand also said it’s highly probable that this flaw could also escalate to a ransomware case.

However, with this vulnerability, Strand said there appears to be relatively few of these ISE systems exposed directly to the open internet. Because of that, Strand didn’t think many organization would be victimized by the initial attack.

“I’d be more concerned about it as a post-exploitation lateral movement opportunity,” said Strand. “An attacker gets into the environment through something else, discovers a vulnerable ISE internally, and uses that to expand access or compound the damage. In a ransomware incident, that’s where I think this vulnerability could become particularly interesting.”

Steve Zurier
Steve Zurier has been a freelance writer and editor for SC Media since 2012. Now, Zurier writes daily news stories and edits SC Media’s Perspectives columns. A long-time member of the tech press, Zurier lives in Columbia, MD. During off-hours, Steve moonlights as an upright bassist for jazz and klezmer bands around the Baltimore/DC area.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds