Cisco Ships a Fix for a Network Access Flaw It Says Is Already Under Attack

Cisco has released fixed software for a flaw in its Identity Services Engine that the company's own security team says is already being exploited.
The advisory, first published on Sept. 16, 2026, covers CVE-2026-76460 in Cisco ISE and in the ISE Passive Identity Connector, or ISE-PIC. ISE is the product that decides which users and devices are let onto a company network, so the check it runs sits in front of everything behind it. Cisco says the flaw is in one of the product's APIs and could let an unauthenticated attacker, working remotely, get past that check and reach the web-based management interface. The company rates the flaw Critical, with a CVSS base score of 10.0, the top of the severity scale, and says it affects ISE and ISE-PIC whatever the device's configuration.
The advisory's section on exploitation says: "The Cisco PSIRT is aware of active exploitation of this vulnerability." PSIRT is the company's product security incident response team.
CISA added the same identifier to its Known Exploited Vulnerabilities catalog on Sept. 16, on evidence of active exploitation, together with CVE-2026-87886 in Acronis Backup. The agency's alert says Binding Operational Directive 26-04 requires federal civilian agencies to prioritize rapid remediation of catalog-listed flaws on publicly exposed assets, and that CISA encourages every other organization to work the same way.
There is no workaround, Cisco says. The fixes are ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. Release 3.0 has reached end of software maintenance and Cisco advises moving to a supported release. Short of upgrading, the advisory names one temporary measure: access control lists that allow only the management traffic a device needs.
Cisco says the flaw was found during the resolution of a Technical Assistance Center support case. The advisory stands at version 1.0, marked final.
