CuraSec

Act active

Cisco ISE CVSS 10.0 Auth Bypass Zero-Day Actively Exploited

2026-09-17 15:32 UTC · The Hacker News · read the source ↗ #cisco#zero-day#authentication-bypass
  • Engineer — Act: Cisco ISE is widely deployed as network access control in enterprise environments; unauthenticated API auth bypass at CVSS 10.0 with CISA KEV listing and public PoC demands immediate action — apply Cisco’s posted mitigation or patch for CVE-2026-76460 and restrict ISE API endpoint exposure at the network layer until patched.
  • SOC/IR — Act: Active exploitation of an ISE auth bypass means attackers may already have bypassed NAC controls; hunt for anomalous unauthenticated API calls against ISE endpoints in your perimeter logs and assume-breach sweep network access audit trails since at least the PoC publication date.
  • Leader — Act: A CVSS 10.0 actively exploited zero-day in Cisco ISE — a core identity and network access control product in most enterprise stacks — warrants same-week action: confirm whether ISE is in use, verify your team is executing Cisco’s mitigations, and prepare a brief for leadership given the likelihood of press coverage and customer security questions.
  • Signals: CVE-2026-76460 — CISA KEV: listed, EPSS n/a, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.