Cisco drops another exploited zero-day, this time a perfect 10
Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack.
Cisco disclosed CVE-2026-76460 on Wednesday, describing it as an authentication bypass affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC).
Successful exploitation can give an unauthenticated remote attacker command execution with root privileges.
Product Security Incident Response Team said it was aware of active exploitation and urged customers to install the fixes immediately.
CISA has also added the vulnerability to its Known Exploited Vulnerabilities catalog.
The warning follows another actively exploited critical vulnerability disclosed days earlier, CVE-2026-76461, affecting its Secure Email Gateway and Secure Email and Web Manager appliances.
That 9.8-rated bug could also lead to root access, prompting Cisco to warn admins that attackers may be able to cover their tracks after getting in.
The latest problem lies in an API within Cisco ISE, the company's network access control platform.
Cisco says insufficient authentication controls on an API endpoint mean an attacker can send a crafted request to bypass the product's web-based management interface.
No credentials or user interaction are required, and Cisco says vulnerable versions of ISE and ISE-PIC are affected regardless of configuration.
The flaw received the maximum CVSS score of 10.0.
Cisco warned that root access could allow attackers to remove or conceal traces of an intrusion, complicating efforts to determine whether an appliance had been breached.
Cisco advised admins to review ISE access logs for suspicious usernames on every node in a distributed deployment and to check network and firewall logs held outside the affected device for signs of unexpected uploads or downloads.
If admins find evidence of possible exploitation, Cisco "strongly recommends" reimaging affected nodes and restoring their configurations from backup if necessary.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.