Close Menu
NCIJ Network NCIJ Network
    What's Hot

    How’s your apocalypse stockpiling coming on? Three weeks in, mine has hit a few snags | Emma Brockes

    September 17, 2026

    Robert Kraft, who blocked Macklemore performances, faced solicitation charge and appeared in Epstein files

    September 17, 2026

    India warns new US tariffs over Russian oil could impact ties | Oil and Gas News

    September 17, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How’s your apocalypse stockpiling coming on? Three weeks in, mine has hit a few snags | Emma Brockes
    • Robert Kraft, who blocked Macklemore performances, faced solicitation charge and appeared in Epstein files
    • India warns new US tariffs over Russian oil could impact ties | Oil and Gas News
    • In Germany’s east, a rare center-left star looks to stem the far right’s rise
    • Tories challenge chancellor to rule out tax rises in budget – UK politics live | Politics
    • Noom Promo Codes: 50% Off Best Deals & Free Trials for September 2026
    • OpenAI Releases a Model Misalignment Disclosure Framework With 3 Review Tracks and 6 Incident Reports From RL Training
    • Cisco warns of max severity ISE zero-day exploited in attacks
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 17
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Cisco warns of max severity ISE zero-day exploited in attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 17, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild.

    Cisco ISE is a centralized policy platform that IT administrators use to manage endpoints, users, and device access to network resources, often while enforcing Zero Trust security models.

    The security flaw (tracked as CVE-2026-76460) lets remote attackers bypass authentication by exploiting a weakness in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of configuration.

    “This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint,” the company explained. “A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.”

    Cisco also warned customers on Wednesday to secure their systems since its Product Security Incident Response Team (PSIRT) flagged CVE-2026-76460 as actively exploited.

    “The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.”

    Because no workarounds exist, applying the security updates is the only recommended course of action to protect networks from ongoing attacks.







    Cisco ISE or ISE-PIC Release First Fixed Release
    3.1 3.1 Patch 12
    3.2 3.2 Patch 11
    3.3 3.3 Patch 12
    3.4 3.4 Patch 7
    3.5 3.5 Patch 4

    Cisco shared indicators of compromise and advised security teams to look for suspicious usernames in access.log files on every node and “strongly” recommended re-imaging the nodes and restoring them from backups if malicious activity is suspected.

    Admins should also cross-check firewall and network logs for signs of suspicious activity (including downloads and uploads from and to external or malicious IP addresses) because attackers may remove evidence of exploitation after obtaining command execution with root privileges.

    Yesterday, Cisco patched a second maximum-severity authentication bypass flaw (CVE-2026-76423) and five other critical security issues (tracked as CVE-2026-76460, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, and CVE-2026-20284) in Cisco ISE and Cisco ISE-PIC, but they have not yet been flagged as actively exploited.

    The Cybersecurity and Infrastructure Security Agency (CISA) also ordered federal agencies to patch their systems against CVE-2026-76460 within three days after adding it to its Known Exploited Vulnerabilities (KEV) Catalog on Wednesday.

    In July 2025, threat actors exploited another Cisco ISE zero-day (CVE-2025-20337) with a maximum severity score in remote code execution attacks to deploy a custom “IdentityAuditAction” web shell disguised as a legitimate ISE component.

    Over the last five years, CISA tagged 99 security flaws in Cisco products as actively exploited in attacks, including seven abused in ransomware attacks.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    attacks Cisco Exploited ISE Max severity warns ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    India warns new US tariffs over Russian oil could impact ties | Oil and Gas News

    Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can’t Install Fix

    Cyber Op Targets South Korean Media & Automotive Sectors

    BragJack Attack Can Turn a Browser’s Agentic AI Against It

    Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

    Webinar: What happens in the first hours of a Google Workspace breach

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    How’s your apocalypse stockpiling coming on? Three weeks in, mine has hit a few snags | Emma Brockes

    September 17, 2026

    Robert Kraft, who blocked Macklemore performances, faced solicitation charge and appeared in Epstein files

    September 17, 2026

    India warns new US tariffs over Russian oil could impact ties | Oil and Gas News

    September 17, 2026

    In Germany’s east, a rare center-left star looks to stem the far right’s rise

    September 17, 2026
    Latest Posts

    What is Trump Media’s Truth API and why is it controversial?

    August 4, 2026

    How ProPublica Tested Hundreds of Omaha Homes for Lead — ProPublica

    August 4, 2026

    Golar LNG raises $600 million loan with FLNG business expansion in mind

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    How’s your apocalypse stockpiling coming on? Three weeks in, mine has hit a few snags | Emma Brockes

    September 17, 2026

    Robert Kraft, who blocked Macklemore performances, faced solicitation charge and appeared in Epstein files

    September 17, 2026

    India warns new US tariffs over Russian oil could impact ties | Oil and Gas News

    September 17, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.