Cisco patches actively exploited zero-day in Identity Services Engine (CVE-2026-76460)
Cisco has issued patches for a maximum-severity flaw in its Identity Services Engine and ISE-PIC products that allows attackers to bypass authentication on an API endpoint and gain unauthorized administrative access, regardless of configuration. Cisco's security team confirmed the vulnerability, tracked as CVE-2026-76460, is being actively exploited and there are no workarounds available, making immediate patching the only defense.