Cisco alerts customers to second actively exploited zero-day in as many days
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Vendors and products
- Cisco
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
Cisco disclosed its second actively exploited zero-day vulnerability in as many days, presenting its customers with back-to-back threats to address in unrelated products.
The latest zero-day — CVE-2026-76460 — has a maximum-severity rating and was exploited before Cisco disclosed and patched the vulnerability Wednesday. The defect in an API of Cisco Identity Services Engine (ISE) allows a remote attacker to bypass authentication and gain full control of the affected device.
“ISE devices enforce network access policy, so root access on the appliance lets an attacker modify that policy, extract stored credentials, delete logs, and move laterally into every network segment ISE controls,” Landon Rice, senior exploit developer at VulnCheck, told CyberScoop.
Cisco did not say how many organizations have been compromised thus far, but reported it found the vulnerability during a technical support case.
“Cisco is aware of active exploitation of this vulnerability. We strongly recommend customers upgrade to available fixed software and follow guidance in the advisory,” a Cisco spokesperson said in a statement.
The Cybersecurity and Infrastructure Security Agency added the zero-day to its known exploited vulnerabilities catalog shortly after Cisco’s disclosure.
Researchers haven’t attributed attacks involving CVE-2026-76460 to any known group or threat actor, but Rice noted Cisco ISE vulnerabilities are a recurring target.
Multiple vulnerabilities affecting the Cisco product have been exploited since June 2025, including CVE-2025-20337 and CVE-2025-20281. The latest zero-day vulnerability and the pair of defects disclosed in the summer of 2025 were all rated critical with the highest rating of 10.
Cisco didn’t say when the first instance of CVE-2026-76460 exploitation occurred, but the disclosure came just two days after the vendor disclosed CVE-2026-76461, an actively exploited zero-day vulnerability in Cisco Secure Email Gateway.
While the two zero-days disclosed this week have consecutive CVE identifiers, there’s no indication they are connected or share any technical relationship, Rice said. “These are different products and different vulnerability classes with no relation,” he added.
A Cisco spokesperson concurred with that assessment. “CVEs are assigned on a first-come, first-served basis, so consecutive numbering reflects assignment order rather than any relationship between the issues. CVE-2026-76460 and CVE-2026-76461 affect different codebases,” the spokesperson added.
Cisco published indicators of compromise to help customers hunt for attempted exploitation in their environments, and said there are no workarounds for the vulnerability.
Latest Podcasts
Government
Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
What’s next for CISA's CDM program that gives cybersecurity tools to federal agencies
Supreme Court denies Trump request to allow USPS mail ballot changes
Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal
Technology
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
European parliament members call for slowdown of Serbia’s EU entry over spyware use
The G7 tells industry to hurry up and prep for post-quantum encryption
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Threats
Five alleged leaders of Black Axe’s operations in South Africa extradited to US
GitLab's critical flaw is already drawing internet-wide probes
Conti ransomware crew member sentenced to four years in prison
Hawley probes OpenAI over Hugging Face breach
Policy
Governments ‘buying time’ in race between innovation, security, national cyber director says
FTC rescinds policy statement requiring health apps to notify customers after a breach
Lawmakers call on Commerce to sanction hackers-for-hire
FBI cyber chief worries private sector not sharing enough cyber threat information
Originally published by CyberScoop. © CyberScoop. Written by Matt Kapko.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-17 21:03 UTC
Related stories
- Apple patches CoreGraphics zero-day flaw exploited in attacks
BleepingComputer · 2026-09-29
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The Hacker News · 2026-09-29
- OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
The Hacker News · 2026-09-29
- One Packet Can Crash OT Servers in Industrial Sectors
Dark Reading · 2026-09-28