Cisco Warns of Second Actively Exploited Zero-Day in Two Days
Cisco has disclosed a second actively exploited zero-day vulnerability in as many days, this time affecting its Identity Services Engine (ISE) product. The flaw, tracked as CVE-2026-76460, carries the highest possible severity rating and allows a remote attacker to bypass authentication and gain full control of an affected device via an API weakness. Because ISE devices enforce network access policy, a compromised device could let attackers alter security policy, steal stored credentials, wipe logs, and move into every network segment the device manages.
Cisco found the vulnerability during a technical support case and has not disclosed how many organisations have been affected. The company has released fixed software and is urging customers to upgrade immediately. The US Cybersecurity and Infrastructure Security Agency has already added the flaw to its Known Exploited Vulnerabilities catalog, and no threat actor has yet been publicly linked to the attacks, though researchers note Cisco ISE has been a recurring target since mid-2025.
This disclosure follows closely behind Cisco's separate warning about CVE-2026-76461, an actively exploited zero-day in its Secure Email Gateway product. Despite the back-to-back timing and consecutive CVE numbers, researchers say the two vulnerabilities are unrelated, affecting different products with different vulnerability types.