Cisco ISE Flaw Rated CVSS 10.0 Exploited to Gain Root Access

Cisco published a security advisory on 16 September confirming that an authentication bypass in its Identity Services Engine (ISE) is already being used in attacks. The bug, tracked as CVE-2026-76460 and catalogued as cisco-sa-ISE-ABP-VNSW7Tn5, carries the maximum CVSS base score of 10.0 and affects both ISE and the ISE Passive Identity Connector (ISE-PIC) "regardless of device configuration," the advisory states. Cisco attributes the flaw to insufficient authentication control on an API endpoint: an unauthenticated, remote attacker who sends a crafted request to that endpoint can bypass the web-based management interface.
The US Cybersecurity and Infrastructure Security Agency added the CVE to its Known Exploited Vulnerabilities catalog the same day, alongside a second actively exploited bug, CVE-2026-87886 in Acronis Backup. CISA's catalog entries give federal civilian agencies until 19 September to act on both under Binding Operational Directive 26-04. "The Cisco Product Security Incident Response Team (PSIRT) is aware of active exploitation of this vulnerability," Cisco's advisory says.
ISE is the system that decides which users and devices are allowed onto a corporate or government network, which is what makes a pre-authentication bug in it so consequential. Cisco warns that after a successful exploit "threat actors may obtain command execution with root privileges," and that at that level of access "evidence of exploitation and indicators of compromise may be removed or hidden by the threat actors." There are no workarounds. The only interim mitigation Cisco offers is infrastructure access control lists that restrict management traffic reaching the appliance. Fixed builds are ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4; release 3.0 has reached end of software maintenance and gets no fix.
The Acronis flaw is narrower but also live. Advisory SEC-10986, published 15 September, describes a local privilege escalation caused by insecure file permissions, rated 7.8. It affects the Acronis Backup plugin for cPanel & WHM, fixed in build 1.9.3.1021, and the Acronis Backup extension for Plesk, fixed in 1.8.11.638. Acronis says exploitation has been detected in the wild "in limited, targeted attacks" against cPanel & WHM deployments.
Neither Cisco, Acronis nor CISA has named who is behind either campaign, or said how many organisations have been hit or when the attacks began. Administrators who cannot patch at once can at least look for compromise: Cisco tells ISE operators to search the appliance's access.log for suspicious usernames on every node of a distributed deployment, and says that if malicious activity is suspected, affected nodes should be re-imaged and restored from a configuration backup.
Sources
- Cisco Security Advisory cisco-sa-ISE-ABP-VNSW7Tn5Primary source
- CISA — Known Exploited Vulnerabilities Catalog alertPrimary source
- Acronis Security Advisory SEC-10986Primary source
- BleepingComputerSecondary
- SecurityWeekSecondary
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- US-China Trade Truce Extended to Jan. 10 as Xi Visits
- Amoeba Breeds at 63°C, Past the 60°C Limit for Complex Life
- 996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
- Oracle Invokes Force Majeure on 2.45GW Stargate Data Center
- Diller Drops $18B MGM Bid; Stock Falls 9.5% to February Levels
- Taylor Swift Adds 4 Songs to ‘Showgirl’ in Sept. 25 Encore
- Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
- Rivian Recalls 98,828 EVs Over Rearview Camera Fault
Comments
No comments yet. Be the first.