Cisco Warns Customers About Second Actively Exploited Zero-Day Vulnerability
Cisco has issued a warning to its customers about a second actively exploited zero-day vulnerability in as many days. The latest vulnerability, CVE-2026-76460, affects an API of Cisco Identity Services Engine (ISE) and allows remote attackers to bypass authentication and gain full control of the affected device.
Landon Rice, senior exploit developer at VulnCheck, said that ISE devices enforce network access policy, so root access on the appliance lets an attacker modify that policy, extract stored credentials, delete logs, and move laterally into every network segment ISE controls.
Cisco did not disclose how many organizations have been compromised thus far but found the vulnerability during a technical support case. The company strongly recommends customers upgrade to available fixed software and follow guidance in the advisory.