Cisco has fixed a maximum-severity zero-day in its Identity Services Engine (ISE), which is being actively exploited, TechRadar reported. The company’s Product Security Incident Response Team (PSIRT) is aware of attacks in the wild.
Tracked as CVE-2026-76460, the vulnerability received a 10/10 critical severity score. Cisco said it affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration.
The flaw is in an ISE API and could allow an unauthenticated, remote attacker to bypass authentication. Cisco said insufficient authentication control on an API endpoint lets an attacker send a crafted request and gain unauthorized access through the web-based management interface.
Cisco said there are no workarounds and urged customers to upgrade to a fixed software release. The US Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies a three-day deadline to patch or stop using ISE entirely. That deadline expires on September 19, 2026.
Cisco also shared Indicators of Compromise (IoC), advising defenders to check access.log files for suspicious usernames. It recommended re-imaging affected nodes and restoring them from backups if a breach occurred.
Comments
0No comments yet. Be the first to comment.