bleeping-computer · Crawled Sep 17, 2026

Cisco warns of max severity ISE zero-day exploited in attacks

Read original article ↗

AI Summary

Cisco has warned of active exploitation of a maximum-severity zero-day vulnerability, CVE-2026-76460, in its Identity Services Engine (ISE) and ISE-PIC software. The flaw allows remote attackers to bypass authentication by exploiting insufficient controls on an API endpoint, enabling unauthorized access to the web-based management interface. No workarounds exist, and Cisco strongly recommends applying security updates immediately. The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies to patch within three days.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.