Cisco has disclosed a maximum-severity flaw in Identity Services Engine (ISE) and ISE-PIC, the software many organisations use to control which devices and users are allowed onto their network. Tracked as CVE-2026-76460 and rated a full 10.0 out of 10 on the CVSS scale, the bug lets an attacker skip the login screen entirely and reach the product's web-based management console — no valid credentials required, and no configuration setting can prevent it.
The root cause is insufficient authentication checking on an API endpoint inside ISE. By sending a crafted request straight to that endpoint, an attacker can bypass the admin login and gain the same access an authenticated administrator would have. Cisco's product security team says it is aware of active exploitation, though it hasn't disclosed who is behind the attacks or how widespread they are. The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on 16 September and has given federal agencies until 19 September to patch, which is about as urgent a timeline as CISA sets.
Cisco has released fixed versions for every supported release line — 3.1 through 3.5 — and says there is no workaround; restricting management-interface access with an access control list is offered only as a stop-gap, not a fix. Patching is the only way to close the hole.
What this means for your business
If your business or your IT provider runs Cisco ISE or ISE-PIC to manage network access — common in offices that use network access control to keep unmanaged devices off the corporate Wi-Fi or LAN — get it onto one of Cisco's patched releases this week; there's no safe way to leave it exposed in the meantime. Because this flaw hands out admin-level access to the console itself, don't stop at applying the patch: ask whoever manages the box to check the ISE administration audit logs for any configuration changes, new admin accounts, or policy edits your team doesn't recognise going back to mid-September. Since ISE is the system deciding who gets network access in the first place, a quiet compromise here could let an attacker add a rogue device or loosen access rules without ever touching an endpoint. If you're not sure whether your network runs ISE at all, that's worth confirming with your IT provider directly — it's exactly the kind of backend infrastructure that isn't visible day to day.