Cisco patches an actively exploited authentication bypass in its ISE network access engine
On September 16, 2026, Cisco shipped a batch of fixes for Identity Services Engine, including CVE-2026-76460, an actively exploited CVSS 10.0 authentication bypass that can yield root. Patch ISE immediately and lock down the management plane with ACLs in the meantime.