Cisco disclosed CVE-2026-76460, a maximum-severity zero-day in Cisco Identity Services Engine (ISE) that was actively exploited before patching. The flaw lets a remote attacker bypass authentication, take full control of the device, and potentially move laterally across networks managed by ISE. #Cisco #CiscoISE #CVE-2026-76460
Keypoints
- Cisco disclosed an actively exploited zero-day in Cisco Identity Services Engine.
- CVE-2026-76460 has a maximum-severity rating and was patched after exploitation began.
- The flaw allows remote authentication bypass and full device compromise.
- Attackers could alter network access policy, extract credentials, and delete logs.
- Cisco also released indicators of compromise and said there is no workaround.
Read More: https://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/