A flaw in Cisco's Identity Services Engine (ISE) and its ISE-PIC variant lets a remote attacker take over the system as root. Cisco has shipped a patch for the bug, tracked as CVE-2026-76460, which carries a severity score of 10 out of 10, the highest possible.
The weakness sits in a single API endpoint. An attacker on the internet can skip the login to the management interface and run commands with root privileges, with no password and no action from a user.
Attacks already underway
Cisco's security team says it is aware of exploitation and urges customers to patch immediately. According to The Register, Cisco found the flaw while working on a Technical Assistance Center support case. The US Cybersecurity and Infrastructure Security Agency (CISA) added it to its catalog of exploited vulnerabilities on September 16.
Fixes exist for versions 3.1, 3.2, 3.3, 3.4, and 3.5. Version 3.0 is no longer supported, so the only way out is an upgrade. Until the patch is in place, Cisco recommends restricting network access to the management interface.
Second in one week
A few days earlier, Cisco patched CVE-2026-76461, a flaw rated 9.8 in its Secure Email Gateway and Web Manager appliances. That bug was also exploited in the wild and also handed attackers root.
ISE is the system companies use to decide who gets onto their network. An attacker who controls it holds the keys to everything behind it.