Skip to content
Back to Guavy Wire
Stocks

Cisco Hit by Second Zero-Day in One Week: Hackers Bypass ISE Authentication

Instruments
CSCO
Share

Cisco has disclosed its second critical vulnerability in just one week, allowing hackers to bypass authentication on its Identity Services Engine (ISE). The ISE is a product that centralizes network access control for a large portion of the enterprise world. A zero-day exploit allows remote attackers to gain full control without credentials or user interaction.

The bug, rated 10 out of 10 in severity, affects all configurations of Cisco ISE and Cisco ISE Passive Identity Connector. There are no workarounds but upgrading to the latest software, which Cisco strongly recommends. The US Cybersecurity and Infrastructure Security Agency (CISA) has added the bug to its Known Exploited Vulnerabilities list, urging federal agencies to update within three days.

Cisco also fixed critical bugs in its Secure Firewall Management Center (FMC), but says it is not aware of any exploitation. However, firewalls are not immune, as multiple newly discovered critical bugs allow hackers to execute arbitrary commands with root privileges.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc