Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

https://www.securityweek.com/wp-content/uploads/2025/09/Cisco-firewall.jpeg

Cisco on Wednesday released urgent patches for a critical-severity authentication bypass vulnerability in Identity Services Engine (ISE) that has been exploited in the wild as a zero-day.

Tracked as CVE-2026-76460 (CVSS score of 10/10), the security defect impacts an API endpoint of the appliance, which does not apply sufficient authentication controls.

This allows an attacker to send crafted requests to the API and bypass the web-based management interface to gain access to the affected device.

Both Cisco ISE and ISE Passive Identity Connector (ISE-PIC) are affected, regardless of device configuration. While no workarounds exist, using infrastructure access control lists (iACLs) to restrict traffic to the affected device prevents remote exploitation.

To resolve the bug, customers should upgrade to ISE or ISE-PIC versions 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11, or 3.1 Patch 12.

“The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more