Cisco has warned of a critical zero-day vulnerability in its Identity Services Engine (ISE) that is under active exploitation. The flaw, tracked as CVE-2026-76460, carries a maximum CVSS score of 10.0 and enables unauthenticated attackers to bypass authentication controls remotely.
According to Cisco's advisory, the vulnerability results from insufficient authentication controls on an API endpoint within ISE. An attacker can exploit this weakness to bypass authentication entirely without credentials.
Cisco ISE is a widely deployed network access control solution that organizations use to enforce security policies and manage user and device access. A successful exploit could provide attackers a foothold for lateral movement, disabling security controls, or accessing sensitive resources.
Cisco emphasized there are no workarounds for this vulnerability. The only mitigation is to apply the provided security updates immediately. The advisory urges all organizations using affected ISE versions to patch as a top priority given the confirmed active exploitation.
Immediate Action Checklist for IT Teams:
- Identify Exposure: Inventory all Cisco ISE deployments and determine the software version.
- Apply Patches: Prioritize deploying fixed versions released by Cisco.
- Review for Compromise: Analyze ISE logs for suspicious API access or anomalous activity.
- Verify Patching: Confirm successful installation of the secure software version.
With no alternative mitigations available, organizations must treat this as an urgent remediation task to protect network access controls from compromise.
Cisco 已針對其身分服務引擎(ISE)中一個正被積極利用的關鍵零日漏洞發出警告。該漏洞編號為 CVE-2026-76460,CVSS 最高嚴重性評分為 10.0,可讓未經驗證的攻擊者遠端繞過驗證控制。
根據 Cisco 通告,該漏洞源於 ISE 內部一個 API 端點的驗證控制不足。攻擊者可利用此弱點,在無需憑證的情況下完全繞過驗證。
Cisco ISE 是廣泛部署的網絡存取控制解決方案,企業用以執行安全政策及管理用戶與設備的存取權限。若遭成功利用,可為攻擊者提供橫向移動、禁用安全控制措施或存取敏感資源的立足點。
Cisco 強調目前尚無解決此漏洞的權宜之計。唯一緩解方法是立即應用提供的安全更新。通告敦促所有使用受影響 ISE 版本的企業,鑑於已確認存在活躍利用行為,應將修補列為最高優先事項。
IT 團隊即時行動清單:
- 識別暴露範圍: 盤點所有 Cisco ISE 部署並確定軟件版本。
- 套用補丁: 優先部署 Cisco 發布的修復版本。
- 審查入侵跡象: 分析 ISE 日誌,查找可疑的 API 存取或異常活動。
- 驗證修補結果: 確認安全軟件版本已成功安裝。
由於無替代緩解方案可用,企業必須將此視為緊急補救任務,以保護網絡存取控制免遭入侵。
