Cisco disclosed its second actively exploited zero-day vulnerability in as many days, presenting its customers with back-to-back threats to address in unrelated products. The latest zero-day — CVE-2026-76460 — has a maximum-severity rating and was exploited before Cisco disclosed and patched the vulnerability Wednesday. The defect in an API of Cisco Identity Services Engine (ISE) allows a remote attacker to bypass authentication and gain full control of the affected device.
Cisco alerts customers to second actively exploited zero-day in as many days
About this summary. This is a short, independently written summary of an article first published by CyberScoop. Cyber Security News did not report or verify the underlying story. Read the original: https://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/

Source attribution: headline and facts are from CyberScoop (cyberscoop.com). Summary method: excerpt of the source description. See our source attribution policy.





