Skip to main content
Security

Cisco patches max-severity ISE zero-day under active exploitation

Cisco patches max-severity ISE zero-day under active exploitation Image: Primary
Cisco released security updates for a maximum-severity authentication bypass in Identity Services Engine and ISE Passive Identity Connector, tracked as CVE-2026-76460, and said its Product Security Incident Response Team is aware of active exploitation. The flaw stems from insufficient authentication control on an API endpoint; a crafted request can bypass the web-based management interface and yield root-level command execution. Cisco reported finding the defect during a technical support case and published indicators of compromise, advising teams to inspect access.log files on every node and re-image suspected systems. No workarounds exist, so applying fixed releases is the recommended remediation. CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch within three days.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Bleeping Computer, cybersecuritynews.com and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI
AI

Moonshot AI's Kimi K3 now available on Amazon Bedrock

AWS has made Kimi K3 from Moonshot AI available on Amazon Bedrock, describing it as the first open-weight model to reach 2.8 trillion parameters. The model combines native vision capabilities with a 1-million-token context window...

AI Infrastructure
AI Infrastructure

AWS launches GPU-aware SageMaker HyperPod Inference Gateway

AWS announced general availability of the SageMaker HyperPod Inference Gateway, a Kubernetes-native routing addon that places inference requests using real-time GPU signals such as KV cache utilization, queue depth, LoRA adapter r...

Security
Security

Cisco warns of actively exploited ISE authentication bypass

Cisco warned that CVE-2026-76460, a maximum-severity flaw in Identity Services Engine and ISE Passive Identity Connector, is being actively exploited. The reported API authentication-control weakness can let an unauthenticated rem...