Cybersecurity

Cisco ISE Flaw Rated CVSS 10.0 Exploited to Gain Root Access

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

Cisco ISE Flaw Rated CVSS 10.0 Exploited to Gain Root Access
Photo: Travis Wise, Wikimedia Commons, CC BY 2.0
0 0
XWhatsAppTelegramLinkedIn

Cisco published a security advisory on 16 September confirming that an authentication bypass in its Identity Services Engine (ISE) is already being used in attacks. The bug, tracked as CVE-2026-76460 and catalogued as cisco-sa-ISE-ABP-VNSW7Tn5, carries the maximum CVSS base score of 10.0 and affects both ISE and the ISE Passive Identity Connector (ISE-PIC) "regardless of device configuration," the advisory states. Cisco attributes the flaw to insufficient authentication control on an API endpoint: an unauthenticated, remote attacker who sends a crafted request to that endpoint can bypass the web-based management interface.

The US Cybersecurity and Infrastructure Security Agency added the CVE to its Known Exploited Vulnerabilities catalog the same day, alongside a second actively exploited bug, CVE-2026-87886 in Acronis Backup. CISA's catalog entries give federal civilian agencies until 19 September to act on both under Binding Operational Directive 26-04. "The Cisco Product Security Incident Response Team (PSIRT) is aware of active exploitation of this vulnerability," Cisco's advisory says.

ISE is the system that decides which users and devices are allowed onto a corporate or government network, which is what makes a pre-authentication bug in it so consequential. Cisco warns that after a successful exploit "threat actors may obtain command execution with root privileges," and that at that level of access "evidence of exploitation and indicators of compromise may be removed or hidden by the threat actors." There are no workarounds. The only interim mitigation Cisco offers is infrastructure access control lists that restrict management traffic reaching the appliance. Fixed builds are ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4; release 3.0 has reached end of software maintenance and gets no fix.

The Acronis flaw is narrower but also live. Advisory SEC-10986, published 15 September, describes a local privilege escalation caused by insecure file permissions, rated 7.8. It affects the Acronis Backup plugin for cPanel & WHM, fixed in build 1.9.3.1021, and the Acronis Backup extension for Plesk, fixed in 1.8.11.638. Acronis says exploitation has been detected in the wild "in limited, targeted attacks" against cPanel & WHM deployments.

Neither Cisco, Acronis nor CISA has named who is behind either campaign, or said how many organisations have been hit or when the attacks began. Administrators who cannot patch at once can at least look for compromise: Cisco tells ISE operators to search the appliance's access.log for suspicious usernames on every node of a distributed deployment, and says that if malicious activity is suspected, affected nodes should be re-imaged and restored from a configuration backup.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.