Smart news for curious minds.

Nerd News Network
Networking

Cisco patches max-severity ISE flaw, the second critical zero-day this week

Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network access control and policy enforcement.

Lead image for “Cisco patches max-severity ISE flaw, the second critical zero-day this week”.
Image: Network World
Share

Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network access control and policy enforcement.

The short version

  • This is the second zero-day flaw Cisco has been forced to release emergency patches for this week, after fixing a critical vulnerability in its Secure Email Gateway appliance .
  • The Cisco ISE flaw, tracked as CVE-2026-76460 , has the maximum severity score of 10.0 on the CVSS scale and can be exploited without authentication to gain root-level privileges on the device.
  • The vulnerability is in an API endpoint used for management and can be exploited by sending crafted requests that bypass the normal web-based management interface completely.

What happened

The flaw affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC) in all configurations and was fixed in versions 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4, depending on which major software release is being used. The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, indicating that exploitation in the wild has been confirmed.

Why it matters

Mitigation Users of Cisco ISE and ISE-PIC are advised to check the access.log on their devices and search for suspicious usernames, which could be an indicator of successful compromise.

Summary by Nerd News Network. Read the full article at Network World via the links above and below.

Share