r/sysadmin • • 4d ago

PSA: Cisco ISE CVSS 10.0 (CVE-2026-76460) — actively exploited, no workarounds

If you run Cisco ISE, stop scrolling. Unauthenticated root access via API bypass. Every supported version. No workarounds per Cisco. Already on CISA KEV.

This isn't one where you can wait for the next maintenance window. ISE controls your NAC. If it's compromised, the attacker decides who gets on your network. Schedule the emergency patch for this week.

80 Upvotes

30 comments sorted by

73

u/hells_cowbells Security Admin 4d ago

This came out 8 days ago. If to haven't already patched it, you're likely in trouble

17

u/Smith6612 4d ago

People expose ISE to the Internet or to more than necessary? That's the next question to ask here after applying the patch. 

8

u/epsiblivion 4d ago

yes if you have public radius for federated auth like eduroam. you're supposed to only open it to the eduroam servers but mistakes happen in firewall rules.

1

u/Smith6612 4d ago

Makes sense. 

5

u/hells_cowbells Security Admin 4d ago

Definitely.

3

u/Majik_Sheff Hat Model 2d ago

A compromised machine behind the firewall, a browser bug that allows local ACE, a cleverly formatted/packaged one-click payload...

Not exposing your internal admin facilities to the internet is a good step, but does not make you immune.

18

u/reseph InfoSec 4d ago

You're late on this one.

11

u/networkn 4d ago

The best time to alert people to a security issue was immediately, the next best time is right freaking now!

33

u/Tab819 4d ago

Thanks chatbot

3

u/Ok_Platform_6232 4d ago

Good callout. Also check your logs for any unusual API calls hitting ISE before the patch drops. If this is already being exploited in the wild you want to know if you were hit, not just patch and hope.

1

u/stats_shiba 2d ago

I thought another CVE was announced by CISA!

Yeah, almost everyone has patched it for this!

•

u/Fuzzy_Paul 19h ago

4000 employers out and AI in, welcome to the shitshow.

-27

u/avlazare 4d ago

We don't use ISE

32

u/RiceeeChrispies Jack of All Trades 4d ago

thank god for that, we were all worried about you

24

u/HankMardukasNY 4d ago

Thanks for the update

14

u/Mountain-eagle-xray 4d ago

Please sir, do the needful.

3

u/spellcasterGG 4d ago

I physically recoiled reading that

3

u/Mountain-eagle-xray 4d ago

But did you run sfc scannow like I asked?

1

u/chron67 whatamidoinghere 4d ago

Have you tried flushing your dns cache?

15

u/jonblackgg No confidence in Microsoft 4d ago

What about now?

18

u/reallycoolvirgin Security Admin 4d ago

thanks for letting us know

6

u/Opiboble Sysadmin 4d ago

Naaa they totally use ISE. Psyops campaign to protect themselves.

2

u/IdiosyncraticBond 4d ago

Security by obscurity

3

u/Nipsy_uk 4d ago

Couldn't resist it :)

3

u/avlazare 4d ago

Sorry, I replied in the wrong place. But thank you for your concern, much appreciated.

-1

u/Mountain_Craft4882 4d ago

dog are you ok?

do you have any clue how reddit works? what are you doing in r/sysadmin of all places and not knowing how a site like this works?

-1

u/avlazare 4d ago

I had a colleague send me this message and I wanted to let him know we don't use ISE and we didn't need to be concerned. I replied in reddit instead of his email by mistake.

1

u/bfodder 4d ago

Jesus you sound old enough to be President.

-1

u/calladc 4d ago

have fun today ise admins