Cisco has issued an alert to customers regarding a second actively exploited zero-day vulnerability discovered within days, affecting its Identity Services Engine (ISE) product. The flaw, identified as CVE-2026-76460, carries a maximum severity rating of 10.0 and was exploited in the wild prior to Cisco's disclosure and subsequent patch release on Wednesday, September 17, 2026.
The vulnerability resides in an API of Cisco ISE, allowing a remote attacker to bypass authentication mechanisms and achieve full control over affected devices. Cisco ISE appliances are critical for enforcing network access policies, meaning root access could enable an attacker to alter these policies, extract stored credentials, delete logs, and facilitate lateral movement across network segments managed by ISE.
Cisco confirmed its awareness of active exploitation and strongly advised customers to upgrade to the available fixed software and adhere to the guidance provided in its advisory. The company stated that it uncovered the vulnerability during a technical support case. Following Cisco's disclosure, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its catalog of known exploited vulnerabilities.
While the specific threat actor or group behind the exploitation of CVE-2026-76460 has not been publicly identified, this marks a recurring pattern for Cisco ISE. The product has been targeted by multiple exploited vulnerabilities since June 2025, including CVE-2025-20337 and CVE-2025-20281, all of which were also rated as critical with a severity score of 10.0.
This latest zero-day disclosure came just two days after Cisco announced CVE-2026-76461, another actively exploited zero-day affecting Cisco Secure Email Gateway. Despite the consecutive CVE identifiers, Cisco has clarified that there is no technical relationship or connection between the two vulnerabilities. They affect different products and codebases, with the consecutive numbering merely reflecting the order of assignment.
Cisco has not specified when the initial exploitation of CVE-2026-76460 occurred. The company has provided indicators of compromise to assist customers in detecting potential exploitation attempts within their environments. There are currently no workarounds available for this vulnerability, making software upgrades the only mitigation.





