Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Summary

Cisco has issued a warning about a critical zero-day vulnerability in its Identity Services Engine (ISE) that is actively being exploited. The flaw, designated CVE-2026-76460, allows unauthenticated remote attackers to bypass authentication mechanisms due to insufficient controls on an API endpoint, earning it a CVSS score of 10.0.

IFF Assessment

FOE

This vulnerability allows attackers to bypass authentication, which is a critical security control, directly enabling unauthorized access.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 19, 2026. Known ransomware use: Unknown.

Defender Context

Defenders must prioritize patching Cisco ISE instances immediately due to this critical zero-day flaw, which is already under active exploitation. The CVSS 10.0 rating indicates a severe risk of unauthorized access, highlighting the need for rapid incident response and vigilant monitoring for any signs of compromise.

Read Full Story →