Cisco’s Perfect-10 ISE Vulnerability: What Las Vegas Businesses Need to Do Right Now
A maximum-severity flaw in Cisco’s network access control platform is already being exploited in the wild — and there is no workaround, only a patch.
Published by CMIT Solutions of Las Vegas · Cybersecurity · 6 min read
A CVSS 10.0 Bug With Attackers Already Inside
On September 17, 2026, Cisco confirmed that a newly disclosed Cisco ISE vulnerability — tracked as CVE-2026-76460 — is being actively exploited in real-world attacks. The flaw affects Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), the centralized platform many mid-sized and enterprise networks use to control which devices and users are allowed onto the network, often as the backbone of a Zero Trust security model.
The vulnerability scores a perfect 10.0 on the CVSS severity scale — the highest possible rating. It stems from insufficient authentication controls on an API endpoint, meaning an attacker doesn’t need a valid username or password at all. A single crafted request to the exposed API lets a remote, unauthenticated attacker bypass the web-based management interface entirely and gain command execution as root — full administrative control of the device, regardless of how it’s configured.
CISA added this flaw to its Known Exploited Vulnerabilities catalog on September 16, 2026, and ordered federal agencies to patch within three days. There is no configuration workaround — the only fix is applying Cisco’s patch, and every day it sits unpatched is a day attackers already know how to walk in the front door.
How the Attack Works
Cisco ISE sits at a uniquely powerful point in a network: it decides which laptops, phones, and IoT devices are trusted enough to connect. Compromising it doesn’t just expose one system — it can hand an attacker the keys to network-wide access policy.
- No credentials required: The attacker sends a specially crafted request directly to a vulnerable API endpoint, bypassing login entirely.
- Root-level access: A successful exploit grants command execution as root, the highest level of system control possible.
- Evidence gets erased: Cisco has warned that attackers may delete logs after gaining root access, which is why it’s telling admins to check access.log files on every node immediately, not just after something looks wrong.
- Not an isolated bug: Cisco patched a second maximum-severity authentication bypass flaw and five other critical vulnerabilities in ISE and ISE-PIC the same week. A separate ISE zero-day was exploited in mid-2025 to install a disguised web shell — this platform has now been a repeated target.
This isn’t Cisco ISE’s first brush with attackers, either. In July 2025, a different maximum-severity ISE flaw was exploited to deploy a custom web shell disguised as a legitimate ISE component — giving attackers persistent, hard-to-detect access. Over the past five years, CISA has tagged 99 separate Cisco product vulnerabilities as actively exploited, including seven abused specifically in ransomware attacks. This is a pattern, not a one-off, and it’s a reminder that “we haven’t been hit yet” is not the same thing as “we’re not a target.”
Why This Matters Even If You’re Not Running ISE Yourself
- ⚠Many Las Vegas hotels, medical groups, law firms, and construction companies rely on managed network infrastructure that uses Cisco gear behind the scenes — you may be exposed without knowing your vendor’s stack
- ⚠A compromised network access control system can let attackers impersonate trusted devices to move laterally into POS systems, EHR platforms, or financial software
- ⚠Root access on a core network device can be used to pivot toward ransomware deployment across every connected system
- ⚠CISA’s three-day federal patch deadline signals how seriously this is being treated — private businesses without a patch-management process routinely take far longer
1. Confirm Whether You’re Exposed
The GapMost business owners have no idea whether their network, or their IT vendor’s infrastructure, runs Cisco ISE or ISE-PIC at all.
The FixAsk your IT provider directly, today, whether any device on your network runs an affected ISE or ISE-PIC version (3.1 through 3.5), and get written confirmation of the patch status.
2. Patch Immediately — There’s No Other Option
The GapUnlike many vulnerabilities, there is no firewall rule or configuration change that mitigates this flaw — only the vendor patch closes it.
The FixUpgrade to the fixed release for your version (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4) immediately, and restrict management-interface access with an infrastructure access control list in the meantime if you can’t patch same-day.
3. Check for Signs You’ve Already Been Hit
The GapBecause attackers can erase evidence after gaining root access, a “no alerts fired” network isn’t proof you’re clean.
The FixReview access.log files on every affected node for suspicious usernames, cross-check firewall logs for unexpected external connections, and if anything looks off, re-image the node and restore from a known-good backup rather than trusting it as-is.
Not sure what’s running on your network? A free assessment tells you exactly what’s exposed, and what to patch first.
Defending Las Vegas with CMIT Solutions
Critical infrastructure vulnerabilities like this one move fast, and most Clark County small businesses don’t have a dedicated security team watching CISA’s exploited-vulnerabilities catalog every morning. CMIT Solutions of Las Vegas does that watching for you — tracking what’s actively being exploited, confirming what’s running on your network, and getting patches applied before attackers find you instead of the other way around. Whether you’re a hotel running guest Wi-Fi authentication, a medical practice segmenting patient devices, or a construction firm managing job-site laptops, the same principle applies: network access control is only as strong as its last patch.
BleepingComputer, “Cisco warns of max severity ISE zero-day exploited in attacks” — bleepingcomputer.com
The Hacker News, “Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks” — thehackernews.com
Protect Your Las Vegas Business Today
A maximum-severity vulnerability with no workaround shouldn’t sit unpatched on your network for another day.
Schedule Your Free Consultation
Prefer to talk? Call (702) 725-2877 or email LVSales@cmitsolutions.com