Jessica Entwistle
September 18 2026
Cisco has issued an emergency patch for a critical zero-day vulnerability in its Identity Services Engine (ISE), tracked as CVE-2026-76460, which is being actively exploited in the wild. The flaw carries a maximum severity rating and allows an unauthenticated attacker to execute arbitrary code on affected systems. This is the second actively exploited Cisco zero-day disclosed in as many days, and the third vulnerability affecting ISE since June 2025. Cisco has confirmed exploitation activity and is urging customers to apply the patch immediately. The vulnerability affects ISE deployments used for network access control, device profiling and policy enforcement across enterprise environments.
Cisco ISE is widely deployed in enterprise networks to manage authentication, authorisation and compliance for users and devices connecting to corporate infrastructure. Active exploitation of a maximum-severity vulnerability in a core identity and access control platform represents significant operational risk. Attackers with access to ISE can potentially bypass network segmentation, escalate privileges, manipulate access policies or establish persistent access to internal systems. The fact that this is the third ISE vulnerability in just over a year suggests that the platform is an attractive and recurring target for threat actors. This pattern underscores the importance of treating identity and access control infrastructure as critical security infrastructure that requires prioritised patching, monitoring and incident response planning. Organisations that rely on ISE for network access control should also consider whether they have sufficient visibility into ISE activity, whether configuration changes are logged and reviewed, and whether their security monitoring can detect anomalous behaviour in identity and access control systems.
Organisations running Cisco ISE should apply the emergency patch as a priority and review whether ISE deployments are appropriately segmented, monitored and protected. Consider whether ISE activity is sufficiently logged and reviewed, whether configuration changes are tracked and approved, and whether your incident response plans account for compromise of identity and access control infrastructure. Organisations should also review whether ISE is deployed with least privilege, whether administrative access is appropriately restricted and monitored, and whether ISE is included in regular vulnerability scanning and patch management processes. Given the recurring pattern of ISE vulnerabilities, organisations may also wish to review whether they have contingency plans for ISE being unavailable or compromised, and whether network access control can continue to operate safely in degraded mode.
Source: CyberScoop