
Cisco Identity Services Engine, the box that decides who and what gets onto your network, had an authentication bypass that scored the maximum possible CVSS: 10.0 out of 10.
CVE-2026-76460 sits in an API endpoint of ISE and the ISE Passive Identity Connector. An unauthenticated remote attacker sends a crafted request to that endpoint and walks into the web-based management interface, no credentials required, thanks to insufficient authentication controls (CWE-648, incorrect use of privileged APIs). From there, successful exploitation can escalate to root-level command execution. Cisco disclosed it and shipped fixes on September 16, already aware that active exploitation was underway, and CISA added it to the Known Exploited Vulnerabilities catalog on confirmation.
Affected versions run from ISE and ISE-PIC 3.1.0 through 3.5.0, across every listed patch level in that range. Fixes landed as 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4.
The part worth sitting with is what ISE actually is: the policy engine that authenticates users and devices and decides what they can reach. An attacker who gets admin on it does not just own one box, they own the decision of who your network trusts. That is precisely the kind of identity and access control infrastructure our firewall and network configuration review is designed to pressure-test, because a perfect policy means nothing if the engine enforcing it can be walked past with one unauthenticated request.