Full Report
The latest zero-day has a maximum-severity rating and affects Cisco Identity Services Engine, a product hit with three actively exploited vulnerabilities since June 2025. The post Cisco alerts customers to second actively exploited zero-day in as many days appeared first on CyberScoop.
Analysis Summary
# Vulnerability: Critical Authentication Bypass in Cisco Identity Services Engine (ISE)
## CVE Details
- **CVE ID:** CVE-2026-76460
- **CVSS Score:** 10.0 (Critical)
- **CWE:** Authentication Bypass (Specific CWE not provided in text, likely CWE-287 or CWE-306)
## Affected Systems
- **Products:** Cisco Identity Services Engine (ISE)
- **Versions:** Specific versions not listed in the article; however, Cisco recommends all customers upgrade to the latest fixed software immediately.
- **Configurations:** The vulnerability resides in an API of the ISE.
## Vulnerability Description
A defect in an API of the Cisco Identity Services Engine allows a remote, unauthenticated attacker to bypass authentication. This flaw permits an attacker to gain full administrative ("root") control of the affected device. Because ISE manages network access policies, an attacker can modify these policies, extract stored credentials, delete logs to hide their tracks, and move laterally across all network segments controlled by the ISE appliance.
## Exploitation
- **Status:** Exploited in the wild (Zero-day)
- **Complexity:** Not explicitly stated, but implies high effectiveness for remote attackers.
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** Total (Ability to extract stored credentials and sensitive network data)
- **Integrity:** Total (Ability to modify network access policies and delete system logs)
- **Availability:** Total (Full control over the appliance and the network segments it manages)
## Remediation
### Patches
- Cisco has released fixed software versions. Customers are strongly advised to consult the [official Cisco Security Advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5) for the appropriate upgrade path for their specific deployment.
### Workarounds
- There are **no available workarounds** for this vulnerability. Patching is the only effective mitigation.
## Detection
- **Indicators of Compromise:** Cisco has published specific IOCs to help customers hunt for attempted exploitation.
- **Detection Methods:** The vulnerability was initially discovered during a technical support case. CISA has added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog. Administrators should review API logs for unusual unauthorized access attempts.
## References
- Cisco Security Advisory: hxxps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
- NVD Listing: hxxps://nvd.nist.gov/vuln/detail/cve-2026-76460
- CyberScoop Report: hxxps://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/