Sploitus Critical Zero-Day Vulnerability in Cisco ISE Under Active Exploitation
Article Content
- •CVE-2026-76460 is a critical zero-day vulnerability in Cisco ISE with a CVSS score of 10.0.
- •The vulnerability allows unauthenticated attackers to bypass authentication via a flawed API endpoint.
- •Cisco has issued urgent patches for affected versions, and CISA has added this vulnerability to its KEV catalog.
Cisco has disclosed a critical vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) that allows unauthenticated remote attackers to bypass authentication via a flaw in an API endpoint. This vulnerability has a CVSS score of 10.0 and is actively being exploited in the wild, prompting Cisco to issue urgent patches for affected versions. The vulnerability impacts both Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration. Cisco has advised customers to upgrade to fixed software releases immediately, as no workarounds are available. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply patches by September 19, 2026. This incident highlights the ongoing risks associated with identity infrastructure vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (72)
Following this threat?
Track Qilin, Sandworm and Cyclops Blink in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…