Join Nostr
2026-09-17 07:06:04 UTC

oxhak on Nostr: Cisco released emergency fixes for CVE-2026-76460, a critical authentication-bypass ...

Cisco released emergency fixes for CVE-2026-76460, a critical authentication-bypass vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Rated CVSS 10.0, the flaw affects an API endpoint that lacks sufficient authentication controls, allowing unauthenticated attackers to bypass the web management interface with crafted requests and access the appliance.

Cisco says the vulnerability is being actively exploited in the wild, but has not attributed the attacks. Successful exploitation can lead to root-privileged command execution, potentially allowing attackers to conceal or delete indicators of compromise. Fixed releases are ISE/ISE-PIC 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11, and 3.1 Patch 12. CISA has added the flaw to its Known Exploited Vulnerabilities catalog.

https://www.securityweek.com/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day/