← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 17, 2026 · 06:39via The Hacker News

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Brief

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.

The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication.

"This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker

Read more on The Hacker News