#1
The Hacker News
general
September 17, 2026 at 06:39 UTC
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
By [email protected] (The Hacker News)
AI Summary
Cisco disclosed CVE-2026-76460, a CVSS 10.0 authentication bypass zero-day in Identity Services Engine (ISE) that allows unauthenticated remote attackers to bypass authentication via crafted API requests. This is the second actively exploited ISE zero-day disclosed in as many days, and ISE has now seen three actively exploited vulnerabilities since June 2025 — making it a critical priority for patching in enterprise environments.
Relevance score: 92.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →