Cisco ISE zero-day (CVSS 10.0) is under active attack — plus WordPress, Tutor LMS and Windows 11 24H2 deadlines

Cisco ISE CVE-2026-76460 (CVSS 10.0) exploited in the wild and added to CISA KEV, plus WordPress 7.1.1, Tutor LMS 4.0.8 and Windows 11 24H2 deadlines.

  • Cisco disclosed CVE-2026-76460 in Identity Services Engine (ISE), a CVSS 10.0 unauthenticated remote authentication bypass that is being exploited in the wild; CISA has added it to the Known Exploited Vulnerabilities catalog.
  • Any organization using ISE for network access control is exposed — a bypass means an attacker can reach protected networks and systems without valid credentials.
  • Separately: update WordPress to 7.1.1 and Tutor LMS to 4.0.8 (subscriber-level RCE, 100,000+ sites), and replace Windows 11 24H2 Home/Pro devices before they stop receiving updates.

What to do now

  1. 1. Patch Cisco ISE today. Open Cisco's security advisory for CVE-2026-76460, identify the fixed release that matches your deployment (appliance, distributed, or cloud), and schedule an emergency change window. If patching cannot happen immediately, apply the vendor's documented mitigations and treat ISE as compromised-adjacent until you do.
  2. 2. Cut off ISE exposure. Restrict the ISE administrative interface and its API to a dedicated management VLAN or a short list of trusted admin hosts. Remove any internet-facing or guest-network-reachable ISE management/API exposure. Disable API access you do not actively use.
  3. 3. Hunt for abuse, then rotate. Review ISE authentication, audit and admin logs for successful logins from unexpected sources, new or modified admin accounts, and unusual policy changes. If you find evidence of a bypass, rotate ISE credentials and any RADIUS/TACACS+ secrets shared with it. Also pull CISA's KEV catalog directly to get the Acronis Backup and Google Pixel CVE IDs and their remediation due dates.
  4. 4. Fix the web tier. Update WordPress core to 7.1.1 (11 security fixes plus core and block-editor bug fixes) and Tutor LMS to 4.0.8. If Tutor LMS cannot be patched right away, deactivate the plugin. Then audit subscriber-level accounts, close open registration if you do not need it, and scan upload directories for webshells.
  5. 5. Plan the Windows 11 exit. Inventory devices running Windows 11 24H2 Home or Pro and upgrade them to a supported release before updates stop in October; confirm the exact date and upgrade path in Microsoft's lifecycle documentation. Patch ABB Ability Edgenius per its ICS advisory (CVE-2026-31431) if you run it.