Cisco ISE zero-day with max severity score exploited in the wild

4 sources
  • Cisco disclosed CVE-2026-76460, a max-severity authentication bypass in its Identity Services Engine that gives attackers root access without credentials.
  • The flaw is the second actively exploited Cisco zero-day in days, part of a 14-advisory batch that also includes critical firewall management bugs.
  • CISA added the vulnerability to its Known Exploited Vulnerabilities catalog Wednesday, giving federal agencies three days to patch.
Sources (4)
  1. 1 Cisco drops another exploited zero-day, this time a perfect 10 www.theregister.com
  2. 2 Cisco warns of max severity ISE zero-day exploited in attacks www.bleepingcomputer.com
  3. 3 Cisco zero-day exploited as critical firewall bugs emerge cybernews.com
  4. 4 U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog securityaffairs.com