← Back to blog Networks

Cisco ISE max-severity zero-day under attack: what to check today if your Mexico sites use Cisco for network access control

3 min read

On September 17, 2026 Cisco warned of a maximum-severity flaw in Identity Services Engine, better known as ISE. It scores CVSS 10, the top of the scale used to rate vulnerabilities, and it is already being used in real attacks, as reported by BleepingComputer.

If your plant, warehouse or office in Mexico runs a Cisco network, ISE is very likely the system deciding who gets on. Here is what it does, why it matters and what to check today, even if your network team sits in another country.

CVSS 10 maximum severity: there is no higher rating
Sep 17, 2026 Cisco advisory, with exploitation already confirmed

What ISE does and why it is the gatekeeper of your network

The network gatekeeper ISE decides which device and which person may connect over wired, Wi-Fi or VPN, and which part of the network they reach.

ISE is a NAC, short for network access control: it inspects every connection before letting it through. When the accountant at your Monterrey office joins the Wi-Fi, ISE asks who they are, whether the laptop belongs to the company and which VLAN it goes to (a VLAN is a separate segment of the network). It does the same for the printer at reception and the VPN of a traveling manager.

That is why compromising it is not losing one more server. Whoever controls ISE can register as a trusted device, drop into the server VLAN and erase their tracks. It is the keys to the whole network. In our experience it is also one of the least patched boxes in a site, because it works and nobody wants to touch it.

First: confirm version and exposure

QuestionWhere to lookWhat you want to see
Which version and patch level is it on?ISE admin console or CLICompare against the affected versions in the Cisco advisory
Does the admin console face the internet?Firewall and NAT rules; test from outsideIt only answers from the management network
Who can log in as administrator?Admin users and groupsOnly accounts that map to active people

The exposed console is what worries us most. We have seen admin access opened for a few days during a rollout from Dallas or Madrid, and it stayed open for years. If your ISE answers from the internet, close it today and keep only the VPN path.

Patching without taking the plant offline

Patch or mitigation, today Follow the Cisco advisory: fixed version where one exists, mitigation where it does not, and a date for the upgrade.

ISE authorizes every connection, so rebooting it mid-morning at a plant with hundreds of devices is a bad idea. The order we follow:

  1. Configuration backup, plus a snapshot if it is virtual.
  2. Confirm what the switches do when ISE stops answering: some modes let everyone in, others cut production off the network.
  3. Upgrade a secondary node first, then the primary, in a window agreed with the plant.
  4. Test with a domain laptop, a printer, an IP phone and one VPN user.

If there is no patch yet for your version, apply the mitigation in the advisory and schedule the upgrade this week, not whenever a window shows up.

Check logs and new accounts

A patch closes the door, but it does not remove whoever is already inside. In the admin logs look for logins at odd hours or from addresses that are not yours, accounts created in recent weeks, changes to authorization policies and network devices nobody asked to add.

No network engineer on site in Mexico?

Local hands Someone who walks into the site, connects to the console if remote access fails and applies what your global team dictates.

This is the most common setup we see: ISE is managed from the US or Europe, while the site in Querétaro has a local IT person who knows Windows, not switches. The change window is at 2 a.m. Central and nobody there has ever plugged in a console cable.

That is what ProcessBi does: on-site review of network gear anywhere in Mexico, patching coordinated with your global team in English, then segmentation and hardening (tightening the configuration: closing unused ports, accounts and services) under a support plan with a written SLA. More on how this works in IT smart hands in Mexico.

ProcessBi technician working on network equipment in a rack
Your team manages ISE from abroad; we are the hands on site in Mexico Foto: Pexels

What about your Mexico operation?

If nobody can tell you today which ISE version your Mexico sites run or whether the console faces the internet, that is the task for today. With an IT support plan network patching gets a calendar and an owner in Mexico.

Request a review of your Cisco network in Mexico — we reply the same business day.

Your path

Running IT in Mexico from abroad

22 of 32
  1. Smart hands ✓ Read You are here 2 min
  2. Remote support ✓ Read You are here 3 min
  3. Nearshoring checklist ✓ Read You are here 2 min
  4. Retail rollouts ✓ Read You are here 2 min
  5. Fake IT support ✓ Read You are here 3 min
  6. Backups that restore ✓ Read You are here 3 min
  7. Secure M365 ✓ Read You are here 3 min
  8. Windows 10 deadline ✓ Read You are here 4 min
  9. Audit app access ✓ Read You are here 3 min
  10. CEO fraud ✓ Read You are here 4 min
  11. Office 2016 cutoff ✓ Read You are here 3 min
  12. Patch today ✓ Read You are here 4 min
  13. Patch VMware ✓ Read You are here 4 min
  14. Office 2021 EOL ✓ Read You are here 3 min
  15. Starlink for sites ✓ Read You are here 3 min
  16. Cardless access ✓ Read You are here 4 min
  17. Control AI on PCs ✓ Read You are here 4 min
  18. ScreenConnect flaw ✓ Read You are here 4 min
  19. Server 2022 EOL ✓ Read You are here 3 min
  20. Exposed cameras ✓ Read You are here 3 min
  21. Domain trust fix ✓ Read You are here 4 min
  22. Patch Cisco ISE ✓ Read You are here 3 min
  23. Protect the plant ✓ Read You are here 3 min
  24. Move to 25H2 ✓ Read You are here 4 min
  25. Outages and UPS ✓ Read You are here 3 min
  26. IT maintenance ✓ Read You are here 4 min
  27. Third-party scripts ✓ Read You are here 3 min
  28. License audit ✓ Read You are here 4 min
  29. Bajío fiber corridor ✓ Read You are here 3 min
  30. Check Point flaw ✓ Read You are here 4 min
  31. Cashless payments ✓ Read You are here 3 min
  32. AI that hacks alone ✓ Read You are here 3 min
  33. Field services
Next A 3 million peso theft from an industrial unit: how to protect your plant or warehouse in Mexico with CCTV, access control and IoT sensors that actually alert someone