Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Second Cisco zero-day in a week, and this one is a 10.0. CVE-2026-76460 lets an unauthenticated attacker bypass auth on an ISE API endpoint and reach root command execution - on the box that decides who gets onto your network. CISA gave federal agencies until September 19 to patch. No workaround; fixes are in 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7 and 3.51 P4. Grep access.log for “dummyuser” before you assume you’re clean.