Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.
Cisco on Wednesday released urgent patches for a critical-severity authentication bypass vulnerability in Identity Services Engine (ISE) that has been exploited in the wild as a zero-day.
Tracked as CVE-2026-76460 (CVSS score of 10/10), the security defect impacts an API endpoint of the appliance, which does not apply sufficient authentication controls.
This allows an attacker to send crafted requests to the API and bypass the web-based management interface to gain access to the affected device.
Source: https://www.securityweek.com/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day/
Related breach coverage
- Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler2026-08-20
Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction. The post Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler appeared first on SecurityWeek.
- Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation2026-09-15
An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek.
- Exploit Published for Fresh Cleo Harmony Vulnerability2026-09-02
The security defect allows remote attackers to bypass authentication through argument bearer manipulation. The post Exploit Published for Fresh Cleo Harmony Vulnerability appeared first on SecurityWeek.
- ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks2026-09-14
The flaw allows attackers to send files and execute them without authorization through an active remote session. The post ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks appeared first on SecurityWeek.