Cisco spent the week rushing out emergency patches for two unrelated, maximum-severity security flaws that hackers were already exploiting in real-world attacks, the networking giant disclosed, capping a run of critical vulnerabilities in its enterprise software this month.
The more severe of the two, tracked as CVE-2026-76460, carries a perfect 10.0 score on the industry's 10-point severity scale. It affects Cisco's Identity Services Engine (ISE) and ISE Passive Identity Connector, software that many large organizations use to control who and what devices can get onto their networks. Cisco said the flaw lets an unauthenticated attacker send a crafted request to an API endpoint, bypass the login screen entirely, and in some cases execute commands with root-level privileges — enough access to erase logs and hide any trace of the intrusion. The company confirmed in its advisory that it is aware of active exploitation and said no workaround exists; customers must upgrade to one of five newly patched software releases.
Days earlier, Cisco had disclosed a second flaw, CVE-2026-76461, rated 9.8, in the AsyncOS software that runs its Secure Email Gateway appliances. According to reporting from The Hacker News, the bug lives in how the gateway parses incoming mail: a specially crafted email containing SQL statements can trigger command execution as root on the underlying operating system, with no user interaction needed beyond the message simply arriving. That flaw, too, was already being exploited before a fix shipped.
A three-day clock for federal agencies
The U.S. Cybersecurity and Infrastructure Security Agency added the ISE flaw to its Known Exploited Vulnerabilities catalog, triggering a binding directive that requires civilian federal agencies to patch by September 19 — a three-day window from the listing. CISA rated the vulnerability as "automatable," meaning attackers could plausibly scan for and exploit vulnerable systems at scale with scripted tools rather than manual effort, and assessed its potential technical impact as total. The email gateway flaw was added to the same KEV catalog days earlier, meaning federal agencies have effectively been racing two separate patch deadlines from the same vendor within a single week.
Cisco has urged administrators to review access logs for suspicious usernames — including a generic "dummyuser" string researchers have flagged as one indicator of compromise — and to check firewall logs for signs that ISE's management interface was reached from unexpected addresses. Because ISE sits at the center of many corporate networks, granting or denying access based on identity, a successful breach there can cascade into far broader compromise than a single stolen credential: an attacker who controls ISE can potentially grant rogue devices trusted network access or lock legitimate ones out.
Neither Cisco nor outside researchers who reported on the flaws have disclosed who is behind the attacks or how many organizations have been compromised so far. Cisco's patched ISE releases are versions 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4; the email gateway fix ships in AsyncOS releases 15.5.5-014, 16.0.4-302 and 16.5.0-780.
Part of a broader pattern this year
Security teams are bracing for more disclosures. Cisco products have accounted for a disproportionate share of actively exploited zero-days across the industry this year, and researchers tracking the company's broader September hardening releases — which also touched its Adaptive Security Appliance, Secure Firewall Threat Defense, Secure Firewall Management Center and IOS XR software — have counted dozens of newly disclosed flaws across its firewall, email and identity product lines in the same release window, several rated at or near the maximum severity score. Enterprise security teams that run multiple Cisco product lines, as many large organizations do, now face the task of triaging and patching several critical advisories simultaneously rather than a single isolated flaw.
For now, the practical guidance from security researchers is unchanged from past Cisco emergencies: patch immediately, assume exposure if patching lagged, and hunt for signs of compromise rather than waiting for confirmation that an attack occurred. With both flaws requiring no authentication and no user interaction to exploit, any internet-facing, unpatched ISE deployment or email gateway remains an open door until updated.