Tuesday, 22 September 2026

Search
Latent Digest

TECHNOLOGY, TRACKED ACROSS DISCIPLINES

Security & Privacy

Cisco Warns of Two Exploited Zero-Days: ISE Auth Bypass and Email Gateway RCE

Two critical Cisco flaws are under active attack, including a maximum-severity authentication bypass in Identity Services Engine.

· 1 min read · 4 sources

Cisco has disclosed two separate zero-day vulnerabilities that are already being exploited in active attacks. The first, CVE-2026-76460, affects the Identity Services Engine (ISE) and carries a perfect CVSS score of 10.0. As reported by Dark Reading, The Register, and The Hacker News, this authentication bypass allows an unauthenticated remote attacker to bypass security controls. The three sources agree on the severity and the active exploitation, noting it follows another Cisco zero-day just days earlier.

The second flaw, CVE-2026-76461, targets AsyncOS Software for Cisco Secure Email Gateway and has a CVSS score of 9.8. The Hacker News reports that this vulnerability enables root command execution, also under active exploitation. While both are critical Cisco zero-days, they affect different products and are tracked separately; the sources do not indicate any shared root cause.

Cisco has issued advisories for both vulnerabilities, and administrators are urged to apply patches immediately. The rapid succession of exploited flaws highlights the ongoing challenge of securing network infrastructure against sophisticated attackers. As the sources note, the ISE flaw in particular is a maximum-severity issue that demands urgent attention.

Sources · 4

  1. 01Cisco Zero-Day Highlights API Endpoint Authentication IssuesDark Reading
  2. 02Cisco drops another exploited zero-day, this time a perfect 10The Register
  3. 03Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active AttacksThe Hacker News
  4. 04Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command ExecutionThe Hacker News

More in Security & Privacy