Circuit Wire — a daily news update from the Circuit.
Cisco disclosed an authentication bypass in its Identity Services Engine on Wednesday and confirmed that attackers are already exploiting it. The flaw, tracked as CVE-2026-76460, carries the maximum CVSS score of 10.0.
ISE is the platform administrators use to control which users and devices reach network resources, often as part of a zero trust setup. Cisco said insufficient authentication control on an API endpoint lets a remote attacker send a crafted request and bypass the web-based management interface. No credentials and no user interaction are required. Vulnerable versions of ISE and the ISE Passive Identity Connector are affected regardless of configuration, and a successful exploit can give command execution with root privileges.
Cisco's Product Security Incident Response Team said it was aware of active exploitation and told customers to upgrade immediately. Fixes are available in ISE and ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. ISE 3.0 has reached the end of software maintenance, so those customers need to migrate to a supported release. There is no workaround, although Cisco said infrastructure access control lists can temporarily restrict management traffic reaching affected systems.
The company published indicators of compromise and told security teams to check ISE access logs on every node for suspicious usernames. It also advised cross-checking firewall and network logs held outside the affected device, because root access lets an intruder remove traces of the intrusion. Where exploitation is suspected, Cisco recommends reimaging the nodes and restoring them from backup.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on Wednesday and gave federal agencies three days to patch. Cisco found the bug while working a Technical Assistance Center support case and has not said who is exploiting it, how long the attacks have run, or what intruders did after getting in. The advisory arrived with a batch of other ISE fixes, including a second maximum-severity authentication bypass, CVE-2026-76423, and five further critical issues. It also follows CVE-2026-76461, an exploited flaw in Cisco Secure Email Gateway and Secure Email and Web Manager disclosed days earlier. Over the past five years CISA has tagged 99 Cisco flaws as actively exploited, seven of them abused in ransomware attacks.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

