Urgent.News

What's breaking now, across thousands of outlets.

Tech

Cisco drops another exploited zero-day, this time a perfect 10

ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch

Cisco drops another exploited zero-day, this time a perfect 10

Cisco has recently disclosed another critical vulnerability, CVE-2026-76460, affecting its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). This authentication bypass flaw allows unauthenticated remote attackers to execute commands with root privileges on compromised systems. The vulnerability has already been actively exploited, and Cisco has urged administrators to install the available patches immediately.

The flaw exists in an API within ISE, which enables attackers to bypass the product's web-based management interface without requiring any user interaction or credentials. Root access granted by this exploit could allow attackers to remove or conceal traces of the intrusion, making it challenging to determine whether a system has been breached.

Cisco recommends reviewing ISE access logs and network logs for suspicious activity and strongly advises admins to reimagine affected nodes and restore their configurations from backups if necessary. No workarounds are currently available, but Cisco suggests using infrastructure access control lists as a temporary mitigation to restrict management and control-plane traffic to affected systems.

Affected versions of ISE and ISE-PIC include 3.0 (end of software maintenance), 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Cisco discovered this vulnerability while resolving a Technical Assistance Center support case and has not disclosed the identity of the attackers or their motives. In addition to this CVE-2026-76460, Cisco released other advisories with high CVSS scores, totaling to a busy month of patching for Cisco administrators.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

More from Thursday 17 September →