The appliance that decides who and what gets onto a hospital network has a maximum-severity hole, and attackers are already through it. Cisco says CVE-2026-76460, a CVSS 10.0 authentication bypass in Identity Services Engine (ISE), is under active exploitation – the second flaw the vendor has flagged as under attack in two days. CISA added it to the Known Exploited Vulnerabilities catalog on September 17.
ISE is the identity-based network access control platform many hospitals use to decide which users, clinical workstations, and connected medical devices reach which part of the network, and to log that access. The bug stems from insufficient authentication control on an API endpoint. A remote, unauthenticated attacker can slip past the web-based management interface and reach the appliance.
Cisco did not detail the observed attacks but published indicators of compromise. Its guidance: check access.log on every node for suspicious usernames and treat any hit as possible malicious activity. Suspected nodes should be re-imaged and restored from a configuration backup. Because intruders may wipe logs, Cisco also urges defenders to cross-check network and firewall logs elsewhere for unexpected uploads to external addresses or downloads from hostile ones. Cisco ISE and the ISE Passive Identity Connector are affected.
Healthcare exposure is direct. A compromised access-control appliance can let an intruder register rogue devices, widen permitted network segments, or hold a position that looks legitimate to every downstream tool. Network teams should sweep logs now and schedule the re-image rather than wait on a patch cycle.