Our takeCISA added CVE-2026-76460 to KEV: actively exploited auth bypass in Cisco ISE that lets unauthenticated remote attackers reach the management interface. Patch now if you run ISE.Cyber Resilience desk
Sources (1)
- cyberscoop · cyberscoop
What this means for you — Security leader:Patch Cisco ISE immediately if you run it; this is the second actively exploited zero-day in the product in two days.
What this means for you — Lean IT orgs:If you use Cisco Identity Services Engine for network access control, apply the update as soon as Cisco releases it.
What this means for you — MSP:Check every client running Cisco ISE and stage the patch as soon as it is available; this marks the fourth actively exploited flaw in ISE since June 2025.
What this means for you — Researcher:Cisco ISE has now seen four actively exploited zero-days since June 2025; track the forthcoming advisory for CVE-2026-76460.