CISCO warned on 16 September 2026 that attackers are actively exploiting a critical vulnerability in its Identity Services Engine (ISE) and ISE-PIC products. Tracked as CVE-2026-76460, the flaw has a CVSS score of 10.0 and stems from insufficient authentication controls on an API endpoint. Unauthenticated remote attackers can send specially crafted network requests to bypass the web management interface and execute commands with root privileges.
Cisco said its Product Security Incident Response Team (PSIRT) was aware of exploitation in the wild; the company reportedly discovered the issue while handling a Technical Assistance Center support case.
Cisco ISE releases 3.1 through 3.5 are affected across all device configurations. Because ISE enforces identity and network-access policies, a compromise could allow attackers to alter access rules and move into internal networks. The article also says attackers may erase logs and advises checking for suspicious entries involving the `dummyuser` account. Cisco has issued fixes in ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4.
There is no temporary workaround, so administrators should apply the relevant update immediately. Where patching cannot be completed at once, infrastructure access-control lists can be used to block untrusted traffic.