Cisco ISE max-severity zero-day under attack: what to check today if your Mexico sites use Cisco for network access control
On September 17, 2026 Cisco warned of a maximum-severity flaw in Identity Services Engine, better known as ISE. It scores CVSS 10, the top of the scale used to rate vulnerabilities, and it is already being used in real attacks, as reported by BleepingComputer.
If your plant, warehouse or office in Mexico runs a Cisco network, ISE is very likely the system deciding who gets on. Here is what it does, why it matters and what to check today, even if your network team sits in another country.
What ISE does and why it is the gatekeeper of your network
ISE is a NAC, short for network access control: it inspects every connection before letting it through. When the accountant at your Monterrey office joins the Wi-Fi, ISE asks who they are, whether the laptop belongs to the company and which VLAN it goes to (a VLAN is a separate segment of the network). It does the same for the printer at reception and the VPN of a traveling manager.
That is why compromising it is not losing one more server. Whoever controls ISE can register as a trusted device, drop into the server VLAN and erase their tracks. It is the keys to the whole network. In our experience it is also one of the least patched boxes in a site, because it works and nobody wants to touch it.
First: confirm version and exposure
| Question | Where to look | What you want to see |
|---|---|---|
| Which version and patch level is it on? | ISE admin console or CLI | Compare against the affected versions in the Cisco advisory |
| Does the admin console face the internet? | Firewall and NAT rules; test from outside | It only answers from the management network |
| Who can log in as administrator? | Admin users and groups | Only accounts that map to active people |
The exposed console is what worries us most. We have seen admin access opened for a few days during a rollout from Dallas or Madrid, and it stayed open for years. If your ISE answers from the internet, close it today and keep only the VPN path.
Patching without taking the plant offline
ISE authorizes every connection, so rebooting it mid-morning at a plant with hundreds of devices is a bad idea. The order we follow:
- Configuration backup, plus a snapshot if it is virtual.
- Confirm what the switches do when ISE stops answering: some modes let everyone in, others cut production off the network.
- Upgrade a secondary node first, then the primary, in a window agreed with the plant.
- Test with a domain laptop, a printer, an IP phone and one VPN user.
If there is no patch yet for your version, apply the mitigation in the advisory and schedule the upgrade this week, not whenever a window shows up.
Check logs and new accounts
A patch closes the door, but it does not remove whoever is already inside. In the admin logs look for logins at odd hours or from addresses that are not yours, accounts created in recent weeks, changes to authorization policies and network devices nobody asked to add.
No network engineer on site in Mexico?
This is the most common setup we see: ISE is managed from the US or Europe, while the site in Querétaro has a local IT person who knows Windows, not switches. The change window is at 2 a.m. Central and nobody there has ever plugged in a console cable.
That is what ProcessBi does: on-site review of network gear anywhere in Mexico, patching coordinated with your global team in English, then segmentation and hardening (tightening the configuration: closing unused ports, accounts and services) under a support plan with a written SLA. More on how this works in IT smart hands in Mexico.
What about your Mexico operation?
If nobody can tell you today which ISE version your Mexico sites run or whether the console faces the internet, that is the task for today. With an IT support plan network patching gets a calendar and an owner in Mexico.
Request a review of your Cisco network in Mexico — we reply the same business day.
Your path
Running IT in Mexico from abroad
22 of 32- Smart hands ✓ Read You are here 2 min
- Remote support ✓ Read You are here 3 min
- Nearshoring checklist ✓ Read You are here 2 min
- Retail rollouts ✓ Read You are here 2 min
- Fake IT support ✓ Read You are here 3 min
- Backups that restore ✓ Read You are here 3 min
- Secure M365 ✓ Read You are here 3 min
- Windows 10 deadline ✓ Read You are here 4 min
- Audit app access ✓ Read You are here 3 min
- CEO fraud ✓ Read You are here 4 min
- Office 2016 cutoff ✓ Read You are here 3 min
- Patch today ✓ Read You are here 4 min
- Patch VMware ✓ Read You are here 4 min
- Office 2021 EOL ✓ Read You are here 3 min
- Starlink for sites ✓ Read You are here 3 min
- Cardless access ✓ Read You are here 4 min
- Control AI on PCs ✓ Read You are here 4 min
- ScreenConnect flaw ✓ Read You are here 4 min
- Server 2022 EOL ✓ Read You are here 3 min
- Exposed cameras ✓ Read You are here 3 min
- Domain trust fix ✓ Read You are here 4 min
- Patch Cisco ISE ✓ Read You are here 3 min
- Protect the plant ✓ Read You are here 3 min
- Move to 25H2 ✓ Read You are here 4 min
- Outages and UPS ✓ Read You are here 3 min
- IT maintenance ✓ Read You are here 4 min
- Third-party scripts ✓ Read You are here 3 min
- License audit ✓ Read You are here 4 min
- Bajío fiber corridor ✓ Read You are here 3 min
- Check Point flaw ✓ Read You are here 4 min
- Cashless payments ✓ Read You are here 3 min
- AI that hacks alone ✓ Read You are here 3 min
- Field services →