Cisco drops another exploited zero-day, this time a perfect 10
ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch
Cisco has recently disclosed a zero-day vulnerability affecting its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). This flaw, identified as CVE-2026-76460, allows an unauthenticated remote attacker to bypass authentication and gain root access to the affected systems. The vulnerability, categorized as a perfect 10 on the CVSS scale, can be exploited without requiring any user interaction or credentials.
The Product Security Incident Response Team at Cisco has confirmed active exploitation of this flaw and strongly advised customers to install the available patches immediately. CISA has also included CVE-2026-76460 in its Known Exploited Vulnerabilities catalog.
The flaw is present in the API of Cisco's network access control platform, and attackers can exploit it by sending a specially crafted request to the web-based management interface. This lack of authentication controls makes the vulnerability particularly dangerous, as attackers can cover their tracks after gaining access. Cisco recommends that affected admins review access logs for suspicious usernames on every node in a distributed deployment and check network and firewall logs outside the affected device for signs of unexpected uploads or downloads.
If evidence of exploitation is found, Cisco recommends reimaging the affected nodes and restoring their configurations from backup.
No permanent workaround exists for this vulnerability. However, administrators can use infrastructure access control lists as a temporary mitigation to restrict management and control-plane traffic to affected systems. Permanent fixes are available in specific patches for ISE and ISE-PIC. Customers running ISE 3.0 must migrate to a supported release, as it has reached the end of software maintenance.
This vulnerability follows another critical flaw disclosed earlier this week, CVE-2026-76461, which also affected Cisco's Secure Email Gateway and Secure Email and Web Manager appliances.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Cisco drops another exploited zero-day, this time a perfect 10 theregister.com