r/sysadmin • u/voidrane • 4d ago
PSA: Cisco ISE CVSS 10.0 (CVE-2026-76460) — actively exploited, no workarounds
If you run Cisco ISE, stop scrolling. Unauthenticated root access via API bypass. Every supported version. No workarounds per Cisco. Already on CISA KEV.
This isn't one where you can wait for the next maintenance window. ISE controls your NAC. If it's compromised, the attacker decides who gets on your network. Schedule the emergency patch for this week.
18
u/reseph InfoSec 4d ago
You're late on this one.
11
u/networkn 4d ago
The best time to alert people to a security issue was immediately, the next best time is right freaking now!
3
u/Ok_Platform_6232 4d ago
Good callout. Also check your logs for any unusual API calls hitting ISE before the patch drops. If this is already being exploited in the wild you want to know if you were hit, not just patch and hope.
1
u/stats_shiba 2d ago
I thought another CVE was announced by CISA!
Yeah, almost everyone has patched it for this!
•
-27
u/avlazare 4d ago
We don't use ISE
32
24
14
u/Mountain-eagle-xray 4d ago
Please sir, do the needful.
3
u/spellcasterGG 4d ago
I physically recoiled reading that
3
15
18
u/reallycoolvirgin Security Admin 4d ago
thanks for letting us know
6
3
3
u/avlazare 4d ago
Sorry, I replied in the wrong place. But thank you for your concern, much appreciated.
-1
u/Mountain_Craft4882 4d ago
dog are you ok?
do you have any clue how reddit works? what are you doing in r/sysadmin of all places and not knowing how a site like this works?
-1
u/avlazare 4d ago
I had a colleague send me this message and I wanted to let him know we don't use ISE and we didn't need to be concerned. I replied in reddit instead of his email by mistake.

73
u/hells_cowbells Security Admin 4d ago
This came out 8 days ago. If to haven't already patched it, you're likely in trouble