CVE Tools

Cisco warns of max severity ISE zero-day exploited in attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedIdentity Services Engine (ISE)ISE Passive Identity Connector (ISE-PIC)

Our summary

Cisco has patched CVE-2026-76460, a maximum-severity authentication bypass affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), which is being exploited in the wild. A crafted request to an affected API can let a remote attacker evade authentication and access the device's web management functions. Organizations should upgrade to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4, as Cisco has not provided a workaround.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store