Summary
Cisco has released a patch for a critical zero-day vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) that is being actively exploited. The flaw, which allows unauthenticated API authentication bypass, has no workarounds, making patching the only solution. CISA has added this bug to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch or disable ISE by September 19, 2026.