Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
- ID
- 25598
- Status
- summarized
- Published
- 17 Sep 2026, 2:39 PM
- Fetched
- 17 Sep 2026, 11:47 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 18 Sep 2026, 12:54 AM
- Tags
- Audience
- developerssaas_founders
What happened
Cisco disclosed a maximum-severity zero-day (CVE-2026-76460, CVSS 10.0) in Identity Services Engine (ISE) and ISE-PIC, actively exploited in the wild. The flaw allows unauthenticated remote attackers to bypass authentication on an API endpoint, potentially gaining root-level command execution. Patches are available across versions 3.1 through 3.5, with no workarounds beyond iACL mitigation.
Why it matters
If your organization runs Cisco ISE for network access control, patch immediately to the listed fixed releases and check access logs for dummyuser entries indicating compromise. For most builders in this audience not managing Cisco ISE deployments, this has no direct action item.
Discussion angle
Brief mention only: if anyone in the group works in enterprise IT or manages network infrastructure, flag this as a patch-now item; otherwise skip to more relevant topics.