Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Cisco Warns of a New Zero-Day Vulnerability in its Identity Services Engine (ISE) that Has Already Been Exploited in Active Attacks


Cisco has warned of a new zero-day vulnerability in its Identity Services Engine (ISE) that has already been exploited in active attacks, highlighting the importance of keeping software up to date and implementing robust security measures to prevent unauthorized access to devices and data.

  • Cisco has issued a warning about a newly discovered zero-day vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) with a maximum-severity security flaw (CVSS score of 10.0).
  • The vulnerability allows an unauthenticated, remote attacker to bypass authentication on the ISE, enabling unauthorized access to the device.
  • Cisco has fixed the issue in software versions 3.1 - Patch 12, 3.2 - Patch 11, and others.
  • Customers are urged to upgrade to a fixed software release to counter the threat.
  • Threat actors may obtain command execution with root privileges, making it difficult to detect evidence of exploitation.
  • Cisco recommends using infrastructure access control lists (iACLs) to allow only required management and control plane traffic.
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.



  • Cisco has issued a warning about a newly discovered zero-day vulnerability in its Identity Services Engine (ISE), which has already been exploited in active attacks. This vulnerability, tracked as CVE-2026-76460, has a CVSS score of 10.0, indicating a maximum-severity security flaw. The vulnerability could allow an unauthenticated, remote attacker to bypass authentication on the ISE, enabling them to gain unauthorized access to the device by bypassing the web-based management interface.

    The issue affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration. Cisco has already fixed the issue in the following software versions: 3.1 - Patch 12, 3.2 - Patch 11, 3.3 - Patch 12, 3.4 - Patch 7, and 3.51 - Patch 4. The company is urging customers to upgrade to a fixed software release to counter the threat.

    According to Cisco, the vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

    Cisco has warned that threat actors may obtain command execution with root privileges upon successful exploitation of this vulnerability, making it difficult to detect evidence of exploitation and indicators of compromise. As a mitigation, customers can use infrastructure access control lists (iACLs) to allow only required management and control plane traffic that is destined to the affected device.

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 19, 2026. This vulnerability is the latest in a series of critical security flaws discovered in Cisco products, including CVE-2026-76461, CVE-2026-20176, CVE-2026-20211, and CVE-2026-20307, among others.

    These vulnerabilities are grouped by CWE category, covering areas such as improper handling of exceptional conditions, improper access control, improper adherence to coding standards, and improper control of a resource through its lifetime. The vulnerabilities affect various Cisco products, including the Secure Firewall Adaptive Security Appliance (ASA), the Cisco Secure Firewall Threat Defense (FTD) Software, the Cisco Secure Firewall Management Center (FMC) Software, the Cisco Nexus Dashboard, and the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager.

    The discovery of this vulnerability highlights the importance of keeping software up to date and applying patches in a timely manner. It also underscores the need for organizations to implement robust security measures, such as infrastructure access control lists (iACLs), to prevent unauthorized access to devices and data.

    In conclusion, the newly discovered zero-day vulnerability in Cisco's Identity Services Engine (ISE) has already been exploited in active attacks. Cisco has issued a warning and provided software patches to address the issue. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. Organizations are urged to apply the patches and implement robust security measures to prevent unauthorized access to devices and data.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Cisco-Warns-of-a-New-Zero-Day-Vulnerability-in-its-Identity-Services-Engine-ISE-that-Has-Already-Been-Exploited-in-Active-Attacks-ehn.shtml

  • https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html


  • Published: Thu Sep 17 12:48:57 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us