Threat Intelligence

Cisco Fixes Critical ISE Flaw Already Under Attack, Plus Rising ClickFix and Browser Threats

The Hacker News · 22 Sept 2026
Key Takeaway If your business uses Cisco ISE, apply the vendor's patch immediately and review access logs for signs of unauthorised entry.

Cisco has issued a warning about a critical vulnerability in its Identity Services Engine (ISE), tracked as CVE-2026-76460, which carries the highest possible severity score of 10.0. The flaw stems from insufficient authentication controls on an API endpoint, allowing an unauthenticated remote attacker to send a crafted request and bypass the web-based management interface entirely. Cisco confirmed the issue is already being actively exploited, making it an urgent priority for any organisation running ISE.

This vulnerability was part of a broader theme in this week's security roundup: attackers exploiting everyday, trusted tools rather than relying on obviously suspicious methods. Reports covered ClickFix style scams that trick users into running malicious commands themselves, browser hijacking attempts, and weaknesses in commonly used plugins and packages. The recurring pattern is that ordinary things people rely on daily, browsers, login pages, software packages, are increasingly the entry point for compromise.

The wider recap also touched on the human side of security, with discussion around moving organisations from simple awareness training toward genuine culture change so secure behaviour becomes second nature rather than a checkbox exercise.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.