Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

theregister+1theregister+1securityaffairs+1Cisco on Wednesday disclosed a maximum-severity authentication bypass vulnerability in its Identity Services Engine that attackers are already exploiting, prompting the U.S. Cybersecurity and Infrastructure Security Agency to order federal agencies to patch within three days.
The flaw, tracked as CVE-2026-76460 and carrying a CVSS score of 10.0, affects Cisco ISE and ISE Passive Identity Connector (ISE-PIC), a centralized platform used widely across enterprises to manage network access control and enforce security policies. The vulnerability stems from insufficient authentication controls on an API endpoint, allowing an unauthenticated remote attacker to send a crafted request, bypass the web-based management interface, and execute commands with root privileges.theregister+2
No credentials, user interaction, or specific device configuration are required for exploitation. No workaround exists.cybernews+2
"The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability," Cisco said in its advisory.bleepingcomputer+1
The disclosure marks the second actively exploited zero-day Cisco has revealed in days. Earlier this week, the company warned of CVE-2026-76461, a 9.8-rated flaw in its Secure Email Gateway and Secure Email and Web Manager appliances that could also lead to root access. Wednesday's advisory batch included 14 critical security advisories in total, with two additional flaws also scoring 10.0 and a trio of remote code execution bugs in Cisco Secure Firewall Management Center scoring as high as 9.9.theregister+1
CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog on Wednesday alongside an Acronis Backup flaw and a Google Pixel cellular modem vulnerability, both also exploited in the wild.securityaffairs
Cisco released fixes in ISE and ISE-PIC versions 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Customers running ISE 3.0, which has reached end of software maintenance, must migrate to a supported release. Cisco advised administrators to review ISE access logs for suspicious usernames across every node and to cross-check firewall and network logs for unexpected uploads or downloads. If evidence of compromise is found, Cisco "strongly recommends" reimaging affected nodes and restoring from backup.bleepingcomputer+1
Cisco discovered the vulnerability while resolving a Technical Assistance Center support case but has not disclosed who is behind the attacks, how long exploitation has been underway, or what the intruders have done after gaining access. The ShadowServer Foundation reported that its honeypots are showing increased scanning activity targeting Cisco vulnerabilities, with hundreds of IPs probing for older flaws.theregister+1