Cisco Urges ISE Users to Patch Zero-Day Exploit Immediately
Cisco has released security updates to address a maximum-severity vulnerability in its Identity Services Engine (ISE) that attackers are actively exploiting. The flaw, tracked as CVE-2026-76460, allows remote attackers to bypass authentication and gain unauthorized access to the affected device by sending a crafted request to an API endpoint.
The Cisco ISE is a centralized policy platform used by IT administrators to manage endpoints, users, and device access to network resources. The company has warned customers that its Product Security Incident Response Team (PSIRT) is aware of active exploitation of the vulnerability, which was added to the Known Exploited Vulnerabilities (KEV) Catalog on Wednesday.
Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability. No workarounds exist, and applying the security updates is the only recommended course of action to protect networks from ongoing attacks.