Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Cisco Patches Critical Zero-Day Flaw Under Active Attack

Published 17 September 2026

Cisco has released an emergency patch for a critical, actively exploited zero-day vulnerability in its Identity Services Engine (ISE) that allows unauthenticated attackers to bypass authentication. The flaw, tracked as CVE-2026-76460, carries a maximum severity score of 10.0 and affects both Cisco ISE and the ISE Passive Identity Connector (ISEPIC), regardless of device configuration. According to Cisco's security advisory, the vulnerability stems from insufficient authentication controls on an API endpoint. An attacker can exploit it by sending a crafted request to the affected endpoint, bypassing the web-based management interface to gain unauthorized access. Cisco's Product Security Incident Response Team (PSIRT) confirmed it is aware of active exploitation in the wild. Successful exploitation could grant attackers command execution with root privileges. This level of access could allow them to remove or hide evidence of a compromise, making detection difficult. Cisco strongly recommends that organizations upgrade to a fixed software release immediately, as no workarounds exist for the vulnerability. The U.S.

0:00 / 0:00