LIVE · cybersecurity feed
Live wire
Cisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEV
vulnerabilityhigh

Cisco alerts customers to second actively exploited zero-day in as many days

The latest zero-day has a maximum-severity rating and affects Cisco Identity Services Engine, a product hit with three actively exploited vulnerabilities since June 2025. The post Cisco alerts customers to second actively exploited zero-day in as many days appeared first on CyberScoop.

zeroday.news ·

Photo: Wikimedia Commons (CC BY 2.5) via Wikimedia Commons

Cisco has issued an alert to customers regarding a second actively exploited zero-day vulnerability discovered within days, affecting its Identity Services Engine (ISE) product. The flaw, identified as CVE-2026-76460, carries a maximum severity rating of 10.0 and was exploited in the wild prior to Cisco's disclosure and subsequent patch release on Wednesday, September 17, 2026.

The vulnerability resides in an API of Cisco ISE, allowing a remote attacker to bypass authentication mechanisms and achieve full control over affected devices. Cisco ISE appliances are critical for enforcing network access policies, meaning root access could enable an attacker to alter these policies, extract stored credentials, delete logs, and facilitate lateral movement across network segments managed by ISE.

Cisco confirmed its awareness of active exploitation and strongly advised customers to upgrade to the available fixed software and adhere to the guidance provided in its advisory. The company stated that it uncovered the vulnerability during a technical support case. Following Cisco's disclosure, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to its catalog of known exploited vulnerabilities.

While the specific threat actor or group behind the exploitation of CVE-2026-76460 has not been publicly identified, this marks a recurring pattern for Cisco ISE. The product has been targeted by multiple exploited vulnerabilities since June 2025, including CVE-2025-20337 and CVE-2025-20281, all of which were also rated as critical with a severity score of 10.0.

This latest zero-day disclosure came just two days after Cisco announced CVE-2026-76461, another actively exploited zero-day affecting Cisco Secure Email Gateway. Despite the consecutive CVE identifiers, Cisco has clarified that there is no technical relationship or connection between the two vulnerabilities. They affect different products and codebases, with the consecutive numbering merely reflecting the order of assignment.

Cisco has not specified when the initial exploitation of CVE-2026-76460 occurred. The company has provided indicators of compromise to assist customers in detecting potential exploitation attempts within their environments. There are currently no workarounds available for this vulnerability, making software upgrades the only mitigation.

vulnerabilityzero-day
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

European Commission set to push social media restrictions, safety requirements into law

The proposal, known as the EU KIDS Act, would block social media platforms from offering accounts to children younger than 13 and establish a bloc-wide minimum age of 15 for account creation.

security

Researchers find way to listen in on headphones from afar

Eve's dropping in on Alice and Bob

security

[Virtual Event] Cybersecurity Outlook 2027

ai

Should you care about an “AI slowdown?”

In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.

malware

China's Salt Typhoon backdoors Latin American orgs with new snooping malware

Beware the SparroWocky, my son! The backdoor that bites…

patch

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two updates posted September 15, AWS said it can no longer recover customer data and resources stored in its Middle East (Bahrain) region, known as me-south-1, or in one availability zone of its Middle East (UA