← Back to feed
DFIREmerging1 sourceSep 18, 2026 · 12:57via AboutDFIR

InfoSec News Nuggets – 09/18/2026

Brief

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

A maximum-severity flaw in Cisco Identity Services Engine and ISE-PIC, tracked as CVE-2026-76460, is being actively exploited to bypass authentication on the web management interface through a crafted request to an insufficiently protected API endpoint, potentially handing attackers root-level command execution. Cisco has released patched versions across the 3. 1 through 3.

5 branches and warns there are no workarounds, only mitigations like restricting management traffic with access control lists, while CISA has ordered federal agencies to patch by September 19.

Read more on AboutDFIR