Cisco has warned of a new maximum-severity security flaw affecting the Identity Services Engine (ISE) This article explores affecting identity services. . It has been resolved in the following versions: 3.1 - Fixed in 3.1 Patch 12, 3.2 - Fixed in 3.2 Patch 11, 3.3 - Fixed in 3.3 Patch 12, 3.4 - Fixed in 3.4 Patch 7, and 3.51 - Fixed in 3.5 Patch 4.
The organization has shared the following command to identify unusual usernames: The presence of any entry in the command output suggests potential malicious activity. There are no workarounds, but customers can mitigate by configuring infrastructure access control lists (iACLs) to allow only necessary management and control plane traffic destined to the affected device." On September 16, 2026, the U.S.
Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog, instructing Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026.




.webp?w=1600&fit=1600,900&ssl=1)





