Cisco Patches Zero-Day Rated CVSS 10.0, Explains Score Only Stopped There Because Scale Does Not Go to 11
The vulnerability, under active exploitation, affects the system that decides who is allowed to log in, which experts note "is kind of the whole thing."
SAN JOSE, Calif. — Cisco issued emergency patches Wednesday for a vulnerability in its Identity Services Engine rated 10.0 on the Common Vulnerability Scoring System, a score the company's security team said understates the situation and was assigned only because the scoring rubric "tops out."
"We asked if there was any way to convey that this one is worse than the other 10.0s," said a Cisco security advisory author who requested anonymity. "They said no, that's what 10 is for. We asked if we could add a 10 with an asterisk. They said the asterisk field is not supported. So it's a 10, and please patch it right now, and I mean now, not after you finish reading this."
The flaw, tracked as CVE-2026-76460, allows an unauthenticated attacker to gain full administrative control of the product responsible for deciding who is allowed on a network. Security researchers described the situation as "the bouncer is unconscious and also the door is missing," and noted that the vulnerability has been actively exploited "since before you were aware of it, probably."
Cisco's advisory recommends that customers patch immediately, and further recommends that customers who cannot patch immediately "reflect on why."
Corporate IT departments across the country spent the day executing emergency change windows, a process one administrator described as "the twenty minutes of the year when the change advisory board stops asking questions." Several organizations reported the patch was applied successfully, while others reported that the patch was applied successfully to a system that the attacker had already patched, "which was courteous."
At press time, Cisco had confirmed no additional vulnerabilities in the product, "as far as we know, and we are actively finding out."