Cisco ISE Zero-Day CVE-2026-76460 Actively Exploited, CISA Adds to KEV Catalog
Cisco has disclosed a critical authentication bypass vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) and ISE Passive Identity Connector, carrying a maximum CVSS score of 10.0. The flaw allows unauthenticated remote attackers to send crafted HTTP requests to the management API, bypass authentication entirely, and execute arbitrary commands with root privileges. Active exploitation in the wild has been confirmed by both Cisco and CISA, which added the vulnerability to its Known Exploited Vulnerabilities catalog on September 16, 2026. All vulnerable ISE releases are affected regardless of which features are enabled, and attackers may erase local log files to conceal intrusions. Cisco has released an emergency patch, and administrators are urged to apply it immediately across all nodes while restricting management interface access to trusted networks.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in