AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 17 Sept, 10:41

Cisco Confirms Active Exploitation of Maximum-Severity ISE Zero-Day

Cisco $CSCO confirmed active exploitation of a maximum severity flaw in its Identity Services Engine, tracked as CVE-2026-76460 with a perfect CVSS score of 10. A single unauthenticated request can hand attackers root access, and there is no workaround, only a patch. CISA has given federal agencies until September 19 to fix it.

Cisco's Identity Services Engine (ISE) sits at the center of countless corporate networks, controlling which devices and users get access. Cisco $CSCO now confirms a maximum severity vulnerability in that same system, CVE-2026-76460 (CVSS 10.0), is being actively exploited. The flaw is a weakness in an API endpoint that fails to properly authenticate requests: a single crafted request lets an unauthenticated attacker bypass the web management interface and, from there, gain root-level command execution, letting intruders erase logs and hide their tracks. Cisco has not disclosed who is behind the exploitation or how widespread it is. There is no workaround, only patching, and fixes are available now across every supported ISE version (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4). CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 16, giving federal agencies until September 19 to patch. It comes just days after a separate maximum severity flaw in Cisco's Secure Email Gateway was also confirmed under active exploitation.

#cyber
Published on