Cisco has addressed a critical security flaw in its Identity Services Engine (ISE), a product used to manage network access and user authentication. The vulnerability, identified as CVE-2026-76460, allows an attacker to bypass authentication without needing login credentials by exploiting a weakness in an application programming interface (API) endpoint. This flaw affects both Cisco ISE and its Passive Identity Connector (ISE-PIC), regardless of how the devices are configured. The issue was rated as the most severe on a 10-point scale, indicating a high risk of exploitation. Cisco’s Product Security Incident Response Team (PSIRT) confirmed that attackers are actively using this vulnerability in the wild. As a result, the company strongly advised customers to update their systems to the latest fixed software version immediately. There are no temporary fixes or workarounds available, and applying the patch is the only way to fully protect against this threat. A detailed list of affected software versions and the corresponding patches is available on Cisco’s official website. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, which tracks security flaws that are currently being used in attacks. This listing requires federal agencies to either patch the issue or stop using the affected ISE systems entirely by September 19, 2026. CISA’s inclusion of the flaw underscores its severity and the urgent need for action. Cisco has also provided security teams with Indicators of Compromise (IoC), which are signs that a system may have been breached. These include suspicious usernames found in access.log files on all network nodes. In the event of a suspected breach, Cisco recommends re-imaging affected systems and restoring them from secure backups. These steps are crucial for ensuring that any potential malicious activity is removed and that systems remain secure.