THU 01 OCT   09:39:06

CISCO FIXES MAXIMUM-SEVERITY FLAW IN NETWORK ACCESS PLATFORM

THU 17 SEP 2026 CYBERSECURITY

Cisco has released fixes for a maximum-severity vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products, which the company says is being actively exploited. The flaw, tracked as CVE-2026-76460, received the highest possible severity score of 10 out of 10. Cisco's Product Security Incident Response Team said the issue stems from insufficient authentication controls on an API endpoint, allowing an unauthenticated remote attacker to send a crafted request and bypass the product's web-based management interface without needing credentials or user interaction. The vulnerability affects all vulnerable versions of ISE and ISE-PIC regardless of how the device is configured. Cisco said no workarounds exist and urged customers to install the fixes immediately.

ISE is Cisco's network access control and identity-based policy platform, used by organisations to determine who and what can connect to their networks and what they can access once inside. The US Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalogue, requiring federal agencies to patch affected systems or take them out of use. Cisco has published indicators of compromise and advised administrators to check access logs on every node for suspicious usernames. The disclosure came days after Cisco warned of another actively exploited flaw affecting its Secure Email Gateway and Secure Email and Web Manager appliances, rated 9.8 in severity, which could also allow an attacker to gain root access.

Cisco has published a full list of affected software versions and corresponding patches alongside its advisory. The Cybersecurity and Infrastructure Security Agency has set federal agencies a deadline of 19 September 2026 to apply the patch or disable ISE entirely. Cisco has not said how many organisations have been affected by the active exploitation. The company continues to urge all customers running the affected products to upgrade to a fixed software release as soon as possible.

WATCHALONGS
LIVE WATCH PARTIES ON YOUTUBE, X AND TWITCH
WATCH NOW >>
SPORTP110
LATEST SCORES RESULTS AND FIXTURES ALL IN ONE PLACE
TO SPORT >>
← BACK