# Cisco patches max-severity ISE zero-day under active exploitation

_Published Thursday, September 17, 2026 at 6:19 PM EDT · Security · Latest · Tier 1 — Major_

![Cisco patches max-severity ISE zero-day under active exploitation — Primary](https://www.bleepstatic.com/content/hl-images/2026/07/02/Cisco.jpg)

Cisco released security updates for a maximum-severity authentication bypass in Identity Services Engine and ISE Passive Identity Connector, tracked as CVE-2026-76460, and said its Product Security Incident Response Team is aware of active exploitation.

The flaw stems from insufficient authentication control on an API endpoint; a crafted request can bypass the web-based management interface and yield root-level command execution. Cisco reported finding the defect during a technical support case and published indicators of compromise, advising teams to inspect access.log files on every node and re-image suspected systems.

No workarounds exist, so applying fixed releases is the recommended remediation. CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch within three days.

## Sources

- [Bleeping Computer](https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/)
- [cybersecuritynews.com](https://cybersecuritynews.com/cisco-warns-of-critical-ise-0-day-vulnerability-exploited/)

---
Canonical: https://techandbusiness.org/newswire/taRbEcMtW3AVmQrF5zuGak
Published: 2026-09-17T22:19:05.722Z
Story chronology: 2026-09-17T07:20:54.000Z
Retrieved: 2026-09-19T02:06:20.627Z
Publisher: Tech & Business (techandbusiness.org)
