What Happened
Cisco shipped emergency patches for CVE-2026-76460, a CVSS 10.0 authentication bypass in Identity Services Engine and ISE Passive Identity Connector, after confirming active exploitation. The flaw sits in an API endpoint lacking sufficient authentication controls, letting a remote attacker send a single crafted request and gain full administrative access to the appliance regardless of configuration. Cisco’s Product Security Incident Response Team says no workaround exists, leaving patching as the only mitigation. CISA added the flaw to its Known Exploited Vulnerabilities catalog and set a September 19 remediation deadline for federal civilian agencies. Read the disclosure from SecurityWeek.
Why This Matters for Canadian Organizations
Identity Services Engine sits at the center of network access control for many large Canadian enterprises, banks, and government networks, deciding which devices and users reach internal systems. A full administrative compromise of ISE gives an attacker the ability to alter access policies across an entire network, opening a path to lateral movement well beyond the appliance itself. Financial institutions operating under OSFI Guideline B-13 and organizations subject to PIPEDA breach-notification rules face direct exposure if ISE deployments remain unpatched past the federal deadline, since a compromised identity control plane undermines the access controls those frameworks assume are in place.
What to Do
Security teams running Cisco ISE or ISE-PIC should apply Cisco’s patches immediately and treat the September 19 KEV deadline as the outside limit rather than a target. Where immediate patching proves impossible, teams should restrict management-plane access to trusted networks only and review ISE logs for unexpected administrative sessions or configuration changes since the flaw became public.






