The Perfect 10

Cisco Identity Services Engine has a CVSS 10.0 authentication bypass vulnerability. CVE-2026-76460. Remote, unauthenticated attackers craft a request, bypass authentication entirely, and execute commands with root privileges on the appliance.

CISA added it to the Known Exploited Vulnerabilities catalog September 16, 2026. Federal Civilian Executive Branch agencies have until today – September 19, 2026 – to patch. Active exploitation confirmed in the wild.

What ISE is

Identity Services Engine is Cisco's network access control platform. It sits at the authentication chokepoint for enterprise networks – decides who gets in, what they can access, enforces policy. ISE authenticates users, devices, endpoints. It integrates with Active Directory, RADIUS, TACACS+, network infrastructure. It's the gatekeeper.

A bypass vulnerability in the gatekeeper is not a hypothetical risk. It's the authentication system itself handing root access to anyone who asks correctly.

The math

CVSS 10.0 is the ceiling. Maximum severity. It requires no authentication, no user interaction, no special conditions. Network accessible. Full system compromise. The only thing between an attacker and root is knowing the right request to send.

Cisco ISE deployments are enterprise and government scale – universities, hospitals, federal agencies, Fortune 500 companies. Every organization running 802.1X network access control, every organization enforcing device posture checks, every organization with BYOD policies that require authentication before network access. ISE is the authentication backbone.

Root access on ISE means:

  • Full network topology visibility
  • RADIUS secrets for authenticating to network devices
  • Active Directory integration credentials
  • VPN authentication databases
  • User and device identity stores
  • Policy configurations showing what's protected and how
  • Logs showing who accessed what and when

An attacker with root on ISE doesn't just bypass authentication. They own the authentication system. They can create accounts, modify policies, grant themselves access to anything the network protects, cover their tracks by editing logs, pivot to every system ISE authenticates to.

The deadline

CISA doesn't set three-day patch deadlines for theoretical risks. Known Exploited Vulnerabilities catalog inclusion means CISA has evidence of active exploitation. Federal agencies got the order September 16. Patch by September 19 or disconnect the system from the network.

Three days is an aggressive timeline. Enterprise patch cycles normally run weeks – test in lab, validate compatibility, schedule maintenance windows, coordinate with change management, deploy in waves. CISA's deadline compresses that to 72 hours because the alternative is unacceptable: leaving a CVSS 10.0 authentication bypass exposed while attackers are actively exploiting it in the wild.

Federal agencies are the named target in CISA's binding operational directive. But every organization running Cisco ISE faces the same risk. The vulnerability doesn't check whether you're a federal agency before it grants root access.

What they're not saying

Cisco's advisory doesn't name the threat actor. It doesn't describe the exploitation technique. It doesn't identify which organizations have been compromised. That's standard operational security during active exploitation – publishing exploitation details helps attackers who haven't figured it out yet.

But the silence tells you something. If this were a research disclosure with no known exploitation, Cisco would say so. If this were limited to a specific configuration or deployment scenario, the advisory would scope it that way. The advisory doesn't scope it because the vulnerability is broad, the exploitation is real, and the urgency is immediate.

CISA's three-day deadline is built on classified or restricted threat intelligence that hasn't been published. Federal agencies got the order because someone in government knows who's exploiting this, how widespread the campaign is, and what they're targeting. The rest of us get the patch deadline and the CVSS score.

The fix

Cisco released patches. Update ISE to the fixed version. If you can't patch immediately, CISA's directive is disconnect from the network. The system can't protect your network if the authentication bypass hands root to anyone who sends the right request.

No workarounds. No mitigations. Patch or disconnect. Those are the options when the vulnerability is authentication bypass with root code execution and active exploitation is confirmed.

The pattern

Cisco perimeter devices are under sustained targeting. Secure Firewall Management Center had two recently-patched flaws exploited by three distinct threat clusters in September – ransomware groups and state-sponsored actors. Secure Email Gateway has a critical zero-day being exploited for root access via malicious emails. Now ISE with a perfect-10 authentication bypass.

Perimeter devices are high-value targets. They're internet-facing, they're trusted, they integrate with core infrastructure, and they're often under-patched because enterprises treat them as appliances rather than attack surfaces. Cisco's visibility into this – emergency patches, CISA KEV listings, active-exploitation disclosures – suggests the threat landscape has shifted. These aren't opportunistic scans. These are focused campaigns against specific Cisco platforms by sophisticated actors.

Federal agencies have until end of day today. Everyone else running Cisco ISE has the same vulnerability, the same active exploitation, and the same risk. The deadline is operational reality, not a compliance checkbox.

Patch or disconnect. There's no third option when the authentication system is the breach.