Urgent.News

What's breaking now, across thousands of outlets.

Tech

Cisco hit by max severity zero-day exploit targeting Identity Services Engine, so it's time to patch up

Both Cisco and CISA are warning about in-the-wild abuse.

Cisco hit by max severity zero-day exploit targeting Identity Services Engine, so it's time to patch up

Cisco has patched a critical zero-day exploit targeting its Identity Services Engine (ISE). The vulnerability, identified as CVE-2026-76460, allows unauthenticated remote attackers to bypass authentication and gain unauthorized access to affected devices. Cisco's Product Security Incident Response Team (PSIRT) has confirmed active exploitation of the flaw.

No workarounds exist; patching is the only solution. The bug is found in both Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), impacting all device configurations. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to patch or disable ISE by September 19, 2026.

Cisco provided Indicators of Compromise (IoC) and advised users to watch for suspicious usernames in log files and consider re-imaging nodes as a precaution.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

SSH Tunnel Manager in Rust: CLI vs Native GUI Trade-offs

🔧 The Problem A few weeks ago a Swift-based macOS SSH tunnel manager started making the rounds here — a menu bar app that lets you spin up local/remote port forwards without touching a terminal.

  • GUI version provides visual status indicators and native features like macOS keychain integration
  • GUI incurs distribution complexity with unsigned builds needing Gatekeeper and SmartScreen warnings

More from Thursday 17 September →