Cisco patches max-severity ISE flaw, the second critical zero-day this week
Summary
Cisco has released patches for a critical authentication bypass vulnerability in its Identity Services Engine (ISE) platform, tracked as CVE-2026-76460. This zero-day flaw allows unauthenticated attackers to gain root-level privileges by exploiting an API endpoint. The vulnerability is actively being exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities catalog.
IFF Assessment
This vulnerability allows unauthenticated attackers to gain root-level privileges on critical network access control devices, posing a significant threat to network security.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: March 22, 2026. Known ransomware use: Known.
Defender Context
This critical vulnerability in Cisco ISE requires immediate attention from network administrators. Defenders should prioritize patching affected systems and monitoring logs for suspicious activity. The fact that it's a zero-day actively exploited in the wild means attackers may already be targeting unpatched environments.