{
  "id": 8022862,
  "title": "Cisco drops another exploited zero-day, this time a perfect 10",
  "url": "https://urgent.news/2026/09/17/cisco-drops-another-exploited-zero-day-this-time-a-perfect-10",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-17T12:40:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/17/cisco-drops-another-exploited-zero-day-this-time-a-perfect-10/5297180"
  },
  "original_language": "en",
  "account": "Cisco has recently disclosed another critical vulnerability, CVE-2026-76460, affecting its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). This authentication bypass flaw allows unauthenticated remote attackers to execute commands with root privileges on compromised systems. The vulnerability has already been actively exploited, and Cisco has urged administrators to install the available patches immediately. The flaw exists in an API within ISE, which enables attackers to bypass the product's web-based management interface without requiring any user interaction or credentials. Root access granted by this exploit could allow attackers to remove or conceal traces of the intrusion, making it challenging to determine whether a system has been breached. Cisco recommends reviewing ISE access logs and network logs for suspicious activity and strongly advises admins to reimagine affected nodes and restore their configurations from backups if necessary. No workarounds are currently available, but Cisco suggests using infrastructure access control lists as a temporary mitigation to restrict management and control-plane traffic to affected systems. Affected versions of ISE and ISE-PIC include 3.0 (end of software maintenance), 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Cisco discovered this vulnerability while resolving a Technical Assistance Center support case and has not disclosed the identity of the attackers or their motives. In addition to this CVE-2026-76460, Cisco released other advisories with high CVSS scores, totaling to a busy month of patching for Cisco administrators.",
  "summary": "ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch",
  "key_points": [
    "Cisco discloses critical CVE-2026-76460 affecting ISE and ISE-PIC",
    "Unauthenticated remote attackers can execute root commands via API exploit",
    "No workarounds, Cisco advises patching and restoring configurations"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Cisco drops another exploited zero-day, this time a perfect 10",
        "url": "https://urgent.news/2026/09/17/cisco-drops-another-exploited-zero-day-this-time-a-perfect-10-8025621",
        "published": "2026-09-17T12:40:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}