ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch.
Cisco disclosed CVE-2026-76460 on Wednesday, describing it as an authentication bypass affecting Identity Services Engine and ISE Passive Identity Connector.
Product Security Incident Response Team said it was aware of active exploitation and urged customers to install the fixes at once.
The warning follows another actively exploited vulnerability disclosed days earlier, CVE-2026-76461, affecting its Secure Email Gateway and Secure Email and Web Manager appliances.
Cisco discovered CVE-2026-76460 while resolving a Technical Help Center support case, but has not disclosed who is exploiting it, how long the attacks have been underway, or what the intruders have done after gaining access.
5 sentences from our version of the report,
chosen to cover it. Nothing here is written; every line is in the article below.
How
Headline check
Headline as published: Cisco drops another exploited zero-day, this time a perfect 10
The one thing this headline claims is in the report.
Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. One claim in this headline could be checked, so this is a narrow pass and not a thorough one. How this is checked
The article, shortened and in plain language
ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch.
Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack.
Cisco disclosed CVE-2026-76460 on Wednesday, describing it as an authentication bypass affecting Identity Services Engine and ISE Passive Identity Connector. Successful exploitation can give an unauthenticated remote attacker command execution with root privileges.
Product Security Incident Response Team said it was aware of active exploitation and urged customers to install the fixes at once. CISA has also added the vulnerability to its Known Exploited Vulnerabilities catalog.
The warning follows another actively exploited vulnerability disclosed days earlier, CVE-2026-76461, affecting its Secure Email Gateway and Secure Email and Web Manager appliances.
Permanent fixes are available in ISE and ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4.
Cisco discovered CVE-2026-76460 while resolving a Technical Help Center support case, but has not disclosed who is exploiting it, how long the attacks have been underway, or what the intruders have done after gaining access.
Shortened to 1 minute
of reading, this version reads 9 on the Niral Score.
You are reading our version, not theirs.
This is The Register's report shortened to its most important sentences, in plainer words, with
verdicts and loaded words taken out. Plain description stays, and so do adjectives
that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations
are theirs — quotations are never edited — and the indicators beside it measure
this version. Hover or tap Adjectives to see every one left in the text.
How this outlet filed it, and how we rewrote it
No other newsroom we read has filed on this event, so there is nothing to compare it with yet.
Readers can ask a question about this story here.
Questions and answers are for subscribers.
Sign in
to read them.
Comments are read before they appear where anything in them needs a person to look.
Nothing posted here is ever deleted; a comment taken down keeps its text and the reason,
so the decision can be looked at again. How this works