Cisco Warns of Two Exploited Zero-Days: ISE Auth Bypass and Email Gateway RCE
Two critical Cisco flaws are under active attack, including a maximum-severity authentication bypass in Identity Services Engine.
Cisco has disclosed two separate zero-day vulnerabilities that are already being exploited in active attacks. The first, CVE-2026-76460, affects the Identity Services Engine (ISE) and carries a perfect CVSS score of 10.0. As reported by Dark Reading, The Register, and The Hacker News, this authentication bypass allows an unauthenticated remote attacker to bypass security controls. The three sources agree on the severity and the active exploitation, noting it follows another Cisco zero-day just days earlier.
The second flaw, CVE-2026-76461, targets AsyncOS Software for Cisco Secure Email Gateway and has a CVSS score of 9.8. The Hacker News reports that this vulnerability enables root command execution, also under active exploitation. While both are critical Cisco zero-days, they affect different products and are tracked separately; the sources do not indicate any shared root cause.
Cisco has issued advisories for both vulnerabilities, and administrators are urged to apply patches immediately. The rapid succession of exploited flaws highlights the ongoing challenge of securing network infrastructure against sophisticated attackers. As the sources note, the ISE flaw in particular is a maximum-severity issue that demands urgent attention.
Sources · 4
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.