Security News

Cybersecurity news aggregator

🌐
CRITICAL Vulnerabilities SecurityWeek

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Cisco has urgently patched a critical authentication bypass vulnerability (CVE-2026-76460, CVSS 10.0) in its Identity Services Engine (ISE) and ISE Passive Identity Connector, which is under active exploitation. The flaw allows unauthenticated remote attackers to send crafted requests to a specific API endpoint, bypassing the web management interface to gain device access. No workarounds exist, but applying infrastructure ACLs to restrict traffic can mitigate remote exploitation; the definitive remediation is to upgrade to the patched versions specified in the advisory.
Read Full Article →

Vulnerabilities Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. By Ionut Arghire | September 17, 2026 (2:19 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Cisco on Wednesday released urgent patches for a critical-severity authentication bypass vulnerability in Identity Services Engine (ISE) that has been exploited in the wild as a zero-day. Tracked as CVE-2026-76460 (CVSS score of 10/10), the security defect impacts an API endpoint of the appliance, which does not apply sufficient authentication controls. This allows an attacker to send crafted requests to the API and bypass the web-based management interface to gain access to the affected device. Both Cisco ISE and ISE Passive Identity Connector (ISE-PIC) are affected, regardless of device configuration. While no workarounds exist, using infrastructure access control lists (iACLs) to restrict traffic to the affected device prevents remote exploitation. To resolve the bug, customers should upgrade to ISE or ISE-PIC versions 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11, or 3.1 Patch 12. “The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability,” the company notes in its advisory . Advertisement. Scroll to continue reading. Cisco has not shared any information on who is behind the attacks. Cybercriminals and state-sponsored threat actors regularly target vulnerabilities in the company’s products. To hunt for potential compromises, organizations should review ‘access.log’ for suspicious usernames. For distributed deployments, the logs for each node should be checked. “The presence of any entry in the output may indicate malicious activity. This should be done on every node in the deployment. If malicious activity is suspected, it is strongly recommended to re-image the affected nodes and restore from configuration backup if needed,” the company says. Additionally, Cisco warns that successful exploitation of CVE-2026-76460 can enable attackers to execute commands with root privileges, which would allow them to hide or delete indicators of compromise (IoCs). Cross-checking network logs and firewall logs outside of the impacted device should help administrators discover potential compromises, including unexpected uploads/downloads. On Wednesday, the US cybersecurity agency CISA added the zero-day to its Known Exploited Vulnerabilities ( KEV ) catalog, urging federal agencies to patch it within three days, in line with BOD 26-04 requirements. Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation Related: Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover Related: Chrome, Firefox Updates Patch 115 Vulnerabilities Related: Acronis Patches Exploited Vulnerability in cPanel Backup Plugin Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire 280,000 Impacted by Premier Medical Group Data Breach Chrome, Firefox Updates Patch 115 Vulnerabilities Acronis Patches Exploited Vulnerability in cPanel Backup Plugin Oracle Patches 800+ Vulnerabilities in September 2026 Security Update Exein Secures $270M at $1.7B Valuation for Physical AI Security Thai Broadband Provider Hacked via Fortinet Vulnerability 240,000 Hit by Data Breach at Japan’s Digital Agency Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases Latest News First Agentic AI Data Breach Reported to Spanish Regulator Virtual Event Today: Attack Surface Management Summit EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media AIUC Raises $40 Million to Certify Enterprise AI Agents Pixel Modem Zero-Day Exploited in Targeted Attacks US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover Hackuity Raises $19 Million for AI-Powered Vulnerability Management Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the Move incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer. Ruben D. Chacon has joined ADM as Vice President and Global CISO. GDIT has appointed retired Maj. Gen. Ryan Heritage as Vice President, Full-Spectrum Cyber. More People On The Move Expert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Share this article