Cisco Drops Another Exploited Zero-Day, This Time a Perfect 10
Cisco, Thursday, September 17th, 2026
The Register reports a CVSS 10.0 Cisco ISE authentication bypass, CVE-2026-76460, is under active attack.
Two days after the Secure Email Gateway scramble, Cisco disclosed CVE-2026-76460, a maximum-severity authentication bypass in Identity Services Engine and ISE Passive Identity Connector.
The flaw carries a perfect CVSS 10.0 score and is already being exploited in the wild.
Because ISE is the policy and network access control plane for many enterprises, an authentication bypass there hands attackers a route into segmented networks.
The Register frames it as the second exploited Cisco zero-day in a single week, leaving admins patching back-to-back critical infrastructure bugs.