Cisco issues emergency patch for critical zero-day vulnerability

Summary

Cisco has released urgent patches for a critical authentication bypass vulnerability, tracked as CVE-2026-76460, in its Identity Services Engine (ISE), which has been actively exploited as a zero-day in the wild. This vulnerability impacts an API endpoint that fails to enforce adequate authentication controls, allowing attackers to bypass management interfaces and potentially execute commands with root privileges. In response to the ongoing threats, the US cybersecurity agency CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated that federal agencies patch it within three days, reflecting the seriousness of the issue. Cisco's Product Security Incident Response Team (PSIRT) has strongly urged all users to upgrade to specified fixed software versions to mitigate risks.

Analysis

Cisco: Cisco Systems develops networking hardware, software, and security solutions for enterprises worldwide. In this incident, the company issued emergency patches for a critical zero-day vulnerability in its Identity Services Engine after confirming active exploitation in the wild. CVE-2026-76460: CVE-2026-76460 is a critical authentication bypass flaw affecting an API endpoint in Cisco Identity Services Engine. The vulnerability allows attackers to gain unauthorized access and has been exploited as a zero-day, prompting an immediate patch release and addition to CISA’s Known Exploited Vulnerabilities catalog. Identity Services Engine: Cisco Identity Services Engine (ISE) is an enterprise network access control and policy enforcement platform. The product, along with its Passive Identity Connector variant, is directly impacted by the actively exploited CVE-2026-76460 vulnerability regardless of configuration. ISE Passive Identity Connector: ISE Passive Identity Connector (ISE-PIC) is a Cisco component that enables passive identity collection for network access policies. It is affected by the same critical authentication bypass vulnerability as the main ISE appliance and requires the same patched versions for remediation. Government Action: CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and directed federal agencies to apply patches within three days. Vulnerability Response: Cisco PSIRT confirmed active exploitation of the flaw and strongly recommended immediate upgrades to fixed releases.

Categories

tech
View Original Tweet