Cisco hit by max severity zero-day exploit targeting Identity Services Engine, so it's time to patch up
- Cisco fixed critical ISE flaw (CVE‑2026‑76460) allowing unauthenticated API authentication bypass
- Actively exploited; no workarounds exist—patching is the only mitigation, per Cisco PSIRT
- CISA added to KEV catalog, mandating federal agencies patch or disable ISE by Sept 19, 2026
Cisco has fixed a maximum-severity vulnerability found in its Identity Services Engine (ISE) that is being actively exploited in attacks.
ISE is the company’s Network Access Control (NAC) and identity-based policy platform which decides who or what is allowed onto a company’s network, and what they’re allowed to access inside.
“A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication,” the company said in a security advisory.
Abused in the wild
“This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful...
Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE