Skip to content

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

  • by

​Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.

The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication.

“This vulnerability is due to insufficient authentication control on an API endpoint,” Cisco said. “An attacker Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.

The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication.

“This vulnerability is due to insufficient authentication control on an API endpoint,” Cisco said. “An attacker  The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *