Skip to content
Critical Zero-Day Vulnerability in Cisco ISE Under Active Exploitation

Critical Zero-Day Vulnerability in Cisco ISE Under Active Exploitation

First seen 16 Sep 2026, 16:30 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 15:48 UTC
  • CVE-2026-76460 is a critical zero-day vulnerability in Cisco ISE with a CVSS score of 10.0.
  • The vulnerability allows unauthenticated attackers to bypass authentication via a flawed API endpoint.
  • Cisco has issued urgent patches for affected versions, and CISA has added this vulnerability to its KEV catalog.

Cisco has disclosed a critical vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) that allows unauthenticated remote attackers to bypass authentication via a flaw in an API endpoint. This vulnerability has a CVSS score of 10.0 and is actively being exploited in the wild, prompting Cisco to issue urgent patches for affected versions. The vulnerability impacts both Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), regardless of device configuration. Cisco has advised customers to upgrade to fixed software releases immediately, as no workarounds are available. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply patches by September 19, 2026. This incident highlights the ongoing risks associated with identity infrastructure vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2025-07-16
CVE-2025-20337 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-14
CVE-2026-90894 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-14
CVE-2026-76461 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-14
CVE-2026-76440 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-14
CVE-2026-76441 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-14
CVE-2026-20353 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-14
CVE-2026-76443 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-14
CVE-2026-76442 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-15
CVE-2026-58704 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
Cisco discloses multiple vulnerabilities
Cisco disclosed nine critical vulnerabilities in ISE, including CVE-2026-76460, which is actively exploited.
The Hacker News

More articles in this cluster (72)

Following this threat?

Track Qilin, Sandworm and Cyclops Blink in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed