logo

Cisco Zero-Day Highlights API Endpoint Authentication Issues

ID: e43188ef-c7ef-5848-824c-16da80f63c0c

STIX ID: report--e43188ef-c7ef-5848-824c-16da80f63c0c

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-09-18

Date Updated: 2026-09-19

Author: Rob Wright

...
...

Cisco disclosed and patched a critical zero-day authentication bypass (CVE-2026-76460) in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that allows unauthenticated attackers to gain root privileges and command execution; the flaw is listed in CISA's Known Exploited Vulnerabilities catalog, affects ISE versions 3.1–3.5 (3.0 is unsupported), and Cisco urges patching and use of iACLs as temporary mitigation while recommending log review for potential IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.