Threat Intelligence

Critical Cisco Zero-Day Puts Identity Systems at Risk

Dark Reading · 19 Sept 2026
Key Takeaway If your business uses Cisco ISE or similar identity and access management tools, apply vendor patches immediately and review who has access to critical systems.

A serious authentication bypass vulnerability, tracked as CVE-2026-76460, has been found in Cisco's Identity Services Engine (ISE). This platform is widely used by organisations to control who and what can access their network. The flaw has received the highest possible severity score of 10 out of 10, meaning it is both easy to exploit and extremely damaging if used by an attacker.

The issue relates to how certain API endpoints handle authentication, potentially allowing attackers to bypass login checks and gain unauthorised access to systems that are meant to be tightly controlled. Because ISE is often used to manage network access decisions, a successful attack could give intruders a foothold into sensitive parts of a business's IT environment.

While this specific product is more common in larger enterprise networks, the underlying issue, weak authentication controls on API endpoints, is a growing problem across many types of business software. Small businesses using Cisco networking products, or any vendor relying on ISE for access control, should check for updates and patches as soon as they are released.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.