Cisco patches actively exploited zero-day in Identity Services Engine
Cisco disclosed and fixed several critical vulnerabilities in its Identity Services Engine and ISE-PIC products, including CVE-2026-76460, a maximum-severity authentication bypass that attackers are already exploiting in the wild. The flaw lets an attacker send a crafted request to an unguarded API endpoint and slip past ISE's web management interface entirely. CISA added the bug to its Known Exploited Vulnerabilities catalog the same day the patch shipped.