HighII Cyber Warfare & Critical Infrastructure16 September 2026, Wednesday
CISA added a Cisco ISE zero-day scored CVSS 10.0 to the KEV catalogue and gave federal agencies 3 days
The flaw, which bypasses authentication entirely, is being actively exploited; Cisco's security team has confirmed the attacks and there is no workaround.
In an alert dated 16 September 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue on the basis of evidence of active exploitation: CVE-2026-76460, an incorrect use of privileged APIs in Cisco's Identity Services Engine (ISE); and CVE-2026-87886, incorrect default permissions in Acronis Backup. CISA's announcement refers to directive BOD 26-04, which obliges federal civilian executive branch agencies to give priority to closing high-risk vulnerabilities in internet-facing assets and, in particular, KEV entries that allow complete takeover of a system after exploitation.
According to SecurityWeek, CVE-2026-76460 was scored 10 out of 10 on the CVSS scale; the flaw allows an unauthenticated remote attacker to reach the affected API endpoint with a crafted request and bypass authentication in the web-based management interface, and successful exploitation makes it possible to execute commands with root privileges. BleepingComputer reported that the affected products are Cisco ISE versions 3.1, 3.2, 3.3, 3.4 and 3.5 together with the ISE Passive Identity Connector, and that the fixes come in versions 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4; there is no workaround, and SecurityWeek wrote that remote exploitation can be blocked with infrastructure access control lists until the patch is applied. Cisco's product security incident response team, PSIRT, confirmed the active exploitation but did not identify the actor behind the attacks. CISA instructed federal agencies to apply the patch within 3 days. Sources conflict on the dates: CISA's own alert is dated 16 September, while SecurityWeek wrote that both the Cisco bulletin and the KEV addition were made on 17 September; BleepingComputer gave the Cisco announcement as 17 September and the KEV addition as 16 September. This divergence could not be independently verified.
Talay assessment
Bottom line
The active exploitation of an authentication bypass scored CVSS 10.0 shows that the identity and access layer of corporate networks is being targeted; in many organisations ISE is the central component controlling network access. Giving federal agencies 3 days is a sign that CISA places the risk in the highest category. The most likely path is mass scanning once the patch is published and a rise in breach cases at organisations that are late to apply it.
Likely effects
- Corporate network securityNegativeWeeks
Because ISE manages network access control, a server taken over with root privileges lets an attacker delete log records and move laterally. Scanning carried out before the patching window closes creates the highest risk.
- Public bodies, critical infrastructureNegativeWeeks
The 3-day patching obligation under BOD 26-04 binds federal agencies, but there is no such obligation for the energy, health and telecoms operators using the same product. The real exposure remains in that second group.
- Corporate users in TürkiyeNegativeWeeks
Cisco ISE is a product widely used in bank, telecoms and public sector networks in Türkiye. The absence of a workaround makes it essential to restrict access with control lists until the patch is applied.
Possibilities, ranked
- 1Widespread scanning, limited breaches55%
Proof-of-concept code circulates once the patch is published and internet-facing ISE instances are scanned en masse, but most organisations patch in time.
Watch: The fall in the number of internet-facing ISE instances in the coming weeks and whether CISA issues a further alert.
- 2It turns into a ransomware campaign30%
The flaw is adopted by ransomware groups as an initial access route and encryption incidents are seen at large organisations.
Watch: Claims of ISE-derived breaches appearing on ransomware groups' leak sites.
- 3It stays focused on state-backed espionage15%
Exploitation remains narrowly targeted, the number of publicly reported cases stays low and the focus is data exfiltration.
Watch: Cisco or CISA attributing the attacker and disclosing which sectors were targeted.
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- CVE-2026-76460 CVSS score▼ 10.0
- Federal patch deadline▼ 3 days
- Affected ISE versions▼ 3.1-3.5