Cisco Identifies Critical Zero-Day Vulnerability in ISE (CVE-2026-76460) with Active Exploitation
Cisco has identified a critical zero-day vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) allowing unauthenticated remote attackers to bypass authentication, with active exploitation reported. The company has released patches, and CISA has added the flaw to its KEV catalog, mandating federal agencies to apply fixes by September 19, 2026.
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.
The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication.
"This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker
*** END OF TRANSMISSION ***