Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Summary
Cisco has issued a warning about a critical zero-day vulnerability in its Identity Services Engine (ISE) that is actively being exploited. The flaw, designated CVE-2026-76460, allows unauthenticated remote attackers to bypass authentication mechanisms due to insufficient controls on an API endpoint, earning it a CVSS score of 10.0.
IFF Assessment
This vulnerability allows attackers to bypass authentication, which is a critical security control, directly enabling unauthorized access.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 19, 2026. Known ransomware use: Unknown.
Defender Context
Defenders must prioritize patching Cisco ISE instances immediately due to this critical zero-day flaw, which is already under active exploitation. The CVSS 10.0 rating indicates a severe risk of unauthorized access, highlighting the need for rapid incident response and vigilant monitoring for any signs of compromise.