Home / Sep 19, 2026 / Story
0
#1 BleepingComputer general September 17, 2026 at 07:20 UTC

Cisco warns of max severity ISE zero-day exploited in attacks

By Sergiu Gatlan

AI Summary

Cisco issued an emergency patch for CVE-2026-76460, a maximum-severity (CVSS 10.0) authentication bypass zero-day in its Identity Services Engine (ISE) that remote, unauthenticated attackers are actively exploiting via crafted API requests. ISE is widely deployed as a network access control solution, making active exploitation of a max-severity auth bypass a critical priority for enterprise security teams to patch immediately.

Relevance score: 88.0/100

# More from September 19