CISA gives federal agencies 3 days to patch two critical Cisco zero-days under active exploit
CISA added two critical Cisco vulnerabilities to its Known Exploited Vulnerabilities catalog within the same week in September, setting patch deadlines of just three days for U.S. federal agencies. The first flaw, CVE-2026-76461, is a root-level remote code execution bug in Cisco Secure Email Gateway triggered by a malicious email requiring no authentication or user interaction. The second, CVE-2026-76460, is an authentication bypass in Cisco Identity Services Engine with a perfect CVSS score of 10.0, affecting the system that controls network access permissions. Both vulnerabilities were already being actively exploited in the wild at the time CISA issued its advisories. Security experts warn that patching alone is insufficient, as attackers may have already planted persistent backdoors on compromised systems before patches are applied.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in