Cisco is addressing a critical zero-day vulnerability in its Identity Services Engine (ISE). The flaw carries the identifier CVE-2026-76460. The vulnerability received a maximum severity score of 10.0. Attackers are actively exploiting the vulnerability to gain root privileges on affected devices. A single crafted request to an API endpoint allows remote, unauthenticated access.

Cisco discovered the breach during a customer support case. The Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog. Federal civilian agencies must patch or disable the ISE service by September 19, 2026.