zero-day Cisco Security Advisory & CISA

Cisco Confirms Active In-The-Wild Exploitation of Maximum-Severity CVSS 10.0 Zero-Day in ISE

Networking vendor Cisco has confirmed active in-the-wild exploitation of a maximum-severity zero-day vulnerability (CVSS 10.0) affecting its Identity Services Engine (ISE). Tracked as CVE-2026-76460, the authentication bypass flaw allows unauthenticated remote attackers to send specially crafted API requests to seize full administrative control over enterprise network access points, triggering immediate inclusion in CISA's KEV catalog.

Cisco Confirms Active In-The-Wild Exploitation of Maximum-Severity CVSS 10.0 Zero-Day in ISE

Networking and cybersecurity infrastructure vendor Cisco has formally acknowledged that a critical zero-day vulnerability assigned maximum severity—CVSS 10.0—is being actively exploited across targeted production networks. The security flaw, tracked as CVE-2026-76460, resides within Cisco Identity Services Engine (ISE), the central policy and network access control platform governing 802.1X access, identity propagation, and posture assessment across global enterprise infrastructure.

Digital forensics and incident response (DFIR) specialists note the critical distinction between this disclosure and the Cisco Firewall Management Center (FMC) security warning issued over the weekend. While FMC governs perimeter packet filtering and firewall rulesets, Cisco ISE operates as the central authentication gatekeeper, determining which endpoints, employees, and mobile devices are permitted access to localized corporate subnets.

According to Cisco's security advisory, the vulnerability stems from deficient API input validation and session handling within ISE's web-based administration subsystem. A remote, unauthenticated adversary possessing network access to the management portal can dispatch deliberately malformed HTTP requests that bypass authentication filters entirely (Authentication Bypass). A successful exploit awards the attacker full administrative control over the ISE platform.

Once an adversary commands the ISE deployment, the consequences for enterprise zero-trust architecture are devastating. Threat actors can modify authorization policies, grant unfettered network access to rogue hardware, collapse network segmentation, and harvest sensitive RADIUS authentication streams.

While a theoretical CVSS 10.0 rating denotes maximum structural vulnerability, Cisco and the US Cybersecurity and Infrastructure Security Agency (CISA) emphasize that in-the-wild exploitation is definitively confirmed. CISA has immediately added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog, compelling federal civilian agencies to remediate exposed instances under strict binding operational directives.

Actionable Guidance for IT and Security Teams

  • Deploy Official Cisco Patches Immediately: Apply Cisco's official software maintenance releases across all standalone, primary, and secondary ISE nodes without delay.
  • Strictly Restrict Management Port Ingress: Administrative and API endpoints (TCP 443 and 8443) must never be accessible from the public internet or untrusted guest VLANs. Enforce strict firewall access-control lists (ACLs) permitting management traffic exclusively from dedicated bastion hosts.
  • Scrutinize Web Engine Telemetry: Inspect `/var/log/httpd/` on all ISE nodes for atypical API POST requests exhibiting invalid session identifiers or unexpected payload structures.
  • Audit Policy Rulesets and Local Administrative Users: Perform a comprehensive audit of active ISE network access policies to detect rogue guest profiles, unauthorized 802.1X bypass exemptions, or newly provisioned administrative accounts.

Evidence Status

  • Confirmed: Cisco released official advisory CVE-2026-76460 (CVSS 10.0) confirming verified in-the-wild exploitation.
  • Reported: CISA indexed the flaw in its KEV catalog; Dark Reading and DFIR researchers documented targeted intrusions.
  • Unconfirmed: Precise attribution regarding whether advanced persistent threat (APT) groups or financially motivated extortionists authored the initial exploit remains under investigation.

In Brief

  • Cisco confirms in-the-wild exploitation of a critical CVSS 10.0 zero-day (CVE-2026-76460) in Identity Services Engine.
  • Remote unauthenticated attackers can bypass authentication to seize root administrative control over enterprise network access.
  • IT teams must patch immediately and restrict ISE management access behind segmented administrative subnets.

Sources & References

← All News Tools