CISOOnline

Cisco patches max-severity ISE flaw, the second critical zero-day this week

Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network access control and policy enforcement. This is the second zero-day flaw Cisco has been forced to release emergency patches for this week, after fixing a critical vulnerability in its Secure Email Gateway appliance.

The Cisco ISE flaw, tracked as CVE-2026-76460, has the maximum severity score of 10.0 on the CVSS scale and can be exploited without authentication to gain root-level privileges on the device. The vulnerability is in an API endpoint used for management and can be exploited by sending crafted requests that bypass the normal web-based management interface completely.

The flaw affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC) in all configurations and was fixed in versions 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4, depending on which major software release is being used.



Source link