{
  "id": 8039717,
  "title": "Cisco hit by max severity zero-day exploit targeting Identity Services Engine, so it's time to patch up",
  "url": "https://urgent.news/2026/09/17/cisco-hit-by-max-severity-zero-day-exploit-targeting-identity",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-17T14:05:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/cisco-hit-by-max-severity-zero-day-exploit-targeting-identity-services-engine-so-its-time-to-patch-up"
  },
  "original_language": "en",
  "account": "Cisco has patched a critical zero-day exploit targeting its Identity Services Engine (ISE). The vulnerability, identified as CVE-2026-76460, allows unauthenticated remote attackers to bypass authentication and gain unauthorized access to affected devices. Cisco's Product Security Incident Response Team (PSIRT) has confirmed active exploitation of the flaw. No workarounds exist; patching is the only solution. The bug is found in both Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), impacting all device configurations. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to patch or disable ISE by September 19, 2026. Cisco provided Indicators of Compromise (IoC) and advised users to watch for suspicious usernames in log files and consider re-imaging nodes as a precaution.",
  "summary": "Both Cisco and CISA are warning about in-the-wild abuse.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}