AKMSecure Insights

When the Zero Trust Gatekeeper Has an Authentication Bypass

Written by AKMSecure | Sep 22, 2026, 1:33:00 PM

Cisco released an emergency patch on September 17 for an authentication bypass in Identity Services Engine, and attackers were already using it. SecurityWeek reported that CVE-2026-76460 carries a CVSS score of 10.0. An unauthenticated remote attacker can send crafted requests to an API endpoint, bypass the web management interface, and execute commands with root privileges. Cisco's PSIRT confirmed active exploitation. CISA added the flaw to the Known Exploited Vulnerabilities catalog the same day, and under BOD 26-04 federal agencies have three days to remediate.

What ISE does in a federal network

Identity Services Engine is a policy decision point. It handles 802.1X authentication, device posture assessment, and network access control, and it supplies the policy that segmentation depends on. It answers one question continuously: is this device allowed on this network, and what is it allowed to reach.

A root-level compromise of that server does not give an attacker one more foothold. It gives them authority over the access decisions the server makes for every segment it governs. Verification still happens. It just no longer means anything.

The same week, three other trust components failed

  • September 14: Russia-linked actors, assessed as Sandworm, chained two Cisco Firewall Management Center flaws (CVE-2026-20079 and CVE-2026-20316) to deploy an upgraded Cyclops Blink implant with network scanning and packet capture, according to Dark Reading.
  • September 15: Cisco disclosed a separate actively exploited zero-day in Secure Email Gateway appliances, added to the KEV catalog on September 14.
  • September 16: NSA, CISA, and allied agencies published joint guidance on the 17 most common Active Directory compromise techniques, several of which abuse certificate services and Kerberos authentication.

These are not four unrelated product bugs. A policy server, a firewall management console, an email gateway, and a directory service with an attached certificate authority are all centralized trust infrastructure. Each one makes security decisions on behalf of everything downstream, and each one is reachable.

Networks have not been maintained as weapon systems

At the Billington CyberSecurity Summit on September 10, Lt. Gen. Paul Stanton, commander of DoD Cyber Defense Command and director of DISA, said the department has spent roughly three decades deferring the maintenance its networks needed. DefenseScoop reported his assessment that "we have not treated our network and our data in the context of a weapon system," and his warning that "static defenses will not work in an era of AI-enabled cyberspace warfare."

He is right about the maintenance debt, and closing it is necessary work. It is also worth being precise about what patching accomplishes. Patching removes the specific defect. It leaves in place the design decision that made the defect worth exploiting.

Zero Trust assumes the verifier cannot be bypassed

The Department of War is targeting Zero Trust across its networks by FY2027. NIST SP 800-207 describes the reference model: a policy decision point evaluates every request, and policy enforcement points act on its answer.

That model concentrates authority by design. The policy decision point becomes the most valuable target on the network, because compromising it invalidates every decision made downstream. PKI has the same shape. A certificate authority vouches for identity across the enterprise, which is why NSA and CISA now publish detection guidance for certificate service abuse.

An architecture that ends in a single high-value verifier has moved the perimeter rather than removed it.

What changes when trust is not centralized

Autonomous Key Management™ replaces PKI with a symmetric-key architecture that has no certificate authority and no central policy server in the trust path. Devices are provisioned once with a crypto seed that algorithmically generates unlimited key material. Peers then authenticate each other directly, and keys refresh with every session.

The practical difference is what an attacker gets for compromising a server. There is no CA to impersonate, no persistent credential to steal and reuse, and no console whose capture confers authority over access decisions elsewhere on the network. Sessions are verified independently, which is what Zero Trust describes at the protocol layer rather than at the policy tier.

AKM does not eliminate emergency patch cycles. It removes the components whose compromise turns a single vulnerability into network-wide authority.

The question for program offices

  • Where does trust terminate in this architecture, and how many systems inherit that decision?
  • If the policy decision point or certificate authority is compromised, what verification still holds?
  • How much of the FY2027 Zero Trust plan depends on components that must stay reachable to function?

About AKMSecure

AKMSecure delivers a patented Autonomous Key Management™ protocol built to replace outdated PKI approaches with a dynamic, quantum-secure, air-gapped-capable architecture. Instead of relying on persistent credentials that can be stolen, reused, or abused, AKM enables independently verified sessions with no standing privileges left behind. The result is a model that better aligns with Zero Trust principles, reduces certificate-based risk, and supports resilient operations across enterprise IT, OT and Tactical Edge environments. Built to NSA-grade security standards and deployable as a lightweight SDK, AKMSecure helps organizations modernize trust at the protocol layer without rebuilding everything around it.