Join Nostr
2026-09-21 15:05:53 UTC

oxhak on Nostr: Cisco has warned that a maximum-severity vulnerability in Identity Services Engine ...

Cisco has warned that a maximum-severity vulnerability in Identity Services Engine (ISE) is being actively exploited. Tracked as CVE-2026-76460 and rated 10.0 on the CVSS scale, the flaw stems from insufficient authentication controls on an API endpoint. An unauthenticated remote attacker can send a specially crafted request to bypass authentication and obtain unauthorized access through the affected device’s web-based management interface.

The incident matters because ISE is used to control and administer network access, while exploitation does not require prior authentication. Organizations running affected ISE deployments should treat the warning as an urgent security issue and consult Cisco’s official security guidance for the applicable remediation.

https://thehackernews.com/2026/09/weekly-recap-cisco-0-day-ai-agent-rce.html