hacker-news · Crawled Sep 17, 2026
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
2 IoCs
Read original article ↗
AI Summary
Cisco has disclosed a critical zero-day vulnerability, CVE-2026-76460, affecting its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that is actively being exploited. The flaw, rated CVSS 10.0, allows unauthenticated remote attackers to bypass authentication by sending a crafted request to an affected API endpoint, potentially leading to full system compromise with root privileges. Cisco confirms active exploitation and advises immediate patching, as no workarounds exist. The U.S. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by September 19, 2026.
AI-extracted · verify before operational use