Cisco released urgent patches for a critical authentication bypass flaw in Identity Services Engine (ISE) and ISE-PIC, tracked as CVE-2026-76460, after confirming active zero-day exploitation. The vulnerability can let attackers bypass the management interface, gain root access, and hide evidence of compromise, prompting CISA to add it to the KEV catalog and require rapid patching. #Cisco #ISE #ISEPIC #CVE202676460 #CISA
Keypoints
- Cisco fixed a critical authentication bypass in Identity Services Engine.
- The flaw is tracked as CVE-2026-76460 with a CVSS score of 10/10.
- Attackers can craft API requests to bypass the web-based management interface.
- Both Cisco ISE and ISE-PIC are affected, and no workaround exists.
- CISA added the zero-day to its Known Exploited Vulnerabilities catalog.
Read More: https://www.securityweek.com/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day/