Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
Cisco released emergency patches for a critical authentication bypass vulnerability CVE-2026-76460 (CVSS 10/10) in Identity Services Engine, which is already being exploited. The attack allows bypassing the web management interface and gaining access to the device, including root privileges. CISA added the vulnerability to its KEV catalog and requires US federal agencies to patch it within three days.
- CVE-2026-76460 received a maximum CVSS score of 10/10
- Affects Cisco ISE and ISE-PIC regardless of configuration
- Fixes: versions 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12 and later
- CISA requires patching within three days under BOD 26-04
Read next
Security