Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

High · The Hacker News ·

Exploited

What happened

Cisco ISE has a CVSS 10.0 zero-day (CVE-2026-76460) allowing unauthenticated remote API auth bypass; actively exploited. Users of affected ISE versions are at risk.

What to do now

Immediately apply Cisco's patch/mitigation; if unavailable, restrict ISE API exposure to trusted networks, disable unused API access, and monitor logs for anomalous auth bypass. Verify affected versions with Cisco advisory.

CVE references

  • CVE-2026-76460

Original source

The Hacker News

AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news