Cisco drops another exploited zero-day, this time a perfect 10

← Back to the feed

Cisco drops another exploited zero-day, this time a perfect 10

The Register · 2 weeks ago

Cisco has disclosed CVE-2026-76460, a critical vulnerability in its Identity Services Engine (ISE) platform that is already being actively exploited in the wild. The flaw, which has received the maximum CVSS severity score of 10.0, allows unauthenticated remote attackers to bypass authentication and execute commands with root privileges on affected systems. This disclosure comes just days after another actively exploited critical vulnerability in Cisco's email gateway products, intensifying pressure on administrators to prioritise patching across their infrastructure.

The vulnerability stems from insufficient authentication controls on an API endpoint within ISE, Cisco's network access control platform. Attackers can send a crafted request to bypass the web-based management interface without requiring any credentials or user interaction. Permanent fixes are available in ISE versions 3.1 Patch 12 through 3.5 Patch 4, although ISE 3.0 has reached end-of-life support. Cisco has advised administrators to review access logs for suspicious activity and check external network and firewall logs for signs of compromise, whilst noting that root access could allow attackers to cover their tracks, and recommending that affected systems be reimaged and restored from backups if exploitation is suspected.

  • Cisco releases critical authentication bypass (CVSS 10.0) actively exploited in ISE platforms
  • Unauthenticated attackers can gain root access; no workaround exists pending patching
  • Second major Cisco zero-day in days; admins must check logs for exploitation evidence

Software

Read the full article at the source →