Cisco is handling two actively exploited zero-days in the same week, and the worse of the pair scores a flat 10.0. CVE-2026-76460 is an authentication bypass in an API endpoint of Identity Services Engine and the ISE Passive Identity Connector. An attacker who can reach the management interface sends a crafted request, skips authentication completely, and ends up on the appliance with root. No credentials needed. No user has to click anything.
CISA put it in the Known Exploited Vulnerabilities catalog on September 17 and gave federal agencies three days to patch under BOD 26-04. That deadline is the story as much as the CVSS score is. The usual window is three weeks.
ISE Is the Worst Box in the Rack to Lose
ISE is not a sensor or a logging tier. It is the policy engine that decides which device gets onto the corporate network, which VLAN it lands in, whether posture checks passed, and which administrators can log into switches and routers through TACACS+. Root on ISE means the attacker is writing the access policy rather than fighting it.
Cisco also warns that root access lets an intruder hide or delete indicators of compromise. So the forensic record of what happened sits on the same box the attacker owns. Teams that patch this week and assume they’re clean are making an assumption the logs can no longer support.
Fixed Releases and the Absence of a Workaround
Cisco says there is no configuration change that mitigates the flaw. Infrastructure access control lists that restrict who can reach the management interface are the only stopgap, and they only help organisations that had segmentation in place before this week. Patched builds are ISE and ISE-PIC 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11 and 3.1 Patch 12.
The second bug, CVE-2026-76461 in Secure Email Gateway, is also rated critical and also under attack. Two exploited flaws in two products in two days points at someone working through the Cisco estate methodically rather than at coincidence.
The Market Reads This as an Appliance Problem
Network edge appliances have been the main road into enterprises for about three years now. Identity brokers, VPN concentrators, mail gateways, file transfer boxes: the pattern repeats because these devices sit at the perimeter, run vendor-controlled code that customers can’t inspect, and hold the credentials that make lateral movement cheap.
Buyers have started to price that in. Procurement teams ask for secure development attestations they didn’t ask for in 2023. Cyber insurers underwrite unpatched edge devices as a named risk. Vendors selling cloud-delivered access control rather than an on-premise appliance will use this quarter’s news in every competitive deal they run, and they’ll win some of them.
None of that helps anyone this week. Patch the box, then check what it did while you weren’t watching.