Cisco warns of max severity ISE zero-day exploited in attacks

Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has released emergency security updates for CVE-2026-76460, a maximum-severity authentication bypass flaw in Cisco Identity Services Engine (ISE) and ISE-PIC that attackers are actively exploiting. The company and CISA urged immediate patching, with Cisco also advising admins to hunt for signs of compromise and re-image affected systems if suspicious activity is found. #CiscoISE #CVE-2026-76460 #CISA

Keypoints

  • Cisco ISE and ISE-PIC are affected by CVE-2026-76460.
  • The flaw allows remote authentication bypass through a vulnerable API endpoint.
  • Cisco confirmed active exploitation and urged immediate upgrades.
  • No workaround exists, so applying fixed releases is the only protection.
  • CISA added CVE-2026-76460 to its KEV Catalog and required fast patching by federal agencies.

Read More: https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/