Hackers Exploit Critical Cisco ISE Flaw to Bypass Authentication and Gain Root Accessnew
Cisco patched CVE-2026-76460, a CVSS 10.0 authentication bypass in ISE and ISE-PIC that can grant unauthenticated attackers root access.
Cisco's advisory cisco-sa-ISE-ABP-VNSW7Tn5 (September 16, 2026) describes CVE-2026-76460, insufficient authentication controls (CWE-648) on an exposed API endpoint in Cisco ISE and ISE-PIC, rated CVSS 10.0. Successful exploitation lets an unauthenticated remote attacker bypass management interface authentication and potentially obtain command-and-control with root privileges, enabling log tampering and persistence. Software updates are available with no workarounds; Cisco urges prioritized patching, log review for suspicious usernames, and reimaging of suspect nodes.