Skip to main content
CiscoLaunch

Cisco drops another exploited zero-day, this time a perfect 10

What happened

Cisco has released security fixes for its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products to address a critical vulnerability.

Source

Article excerpt

security ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack. Cisco disclosed CVE-2026-76460 on Wednesday, describing it as an authentication bypass affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Successful exploitation can give an unauthenticated remote attacker command execution with root privileges. Product Security Incident Response Team said it was aware of active exploitation and urged customers to install the fixes immediately. CISA has also added the vulnerability to its Known Exploited Vulnerabilities catalog. The warning follows another actively exploited critical vulnerability disclosed days earlier, CVE-2026-76461, affecting its Secure Email Gateway and Secure Email and Web Manager appliances. That 9.8-rated bug could also lead to root access, prompting Cisco to warn admins that attackers may be able to cover their tracks after getting in. The latest problem lies in an API within Cisco ISE, the company's network access control platform. Cisco says insufficient authentication controls on an API endpoint mean an attacker can send a crafted request to bypass the product's web-based management interface. No credentials or user...

Keep reading with a free account

The rest of this article, and every signal for Cisco, is in your free account.

Extracted from this sentence

Permanent fixes are available in ISE and ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4.

Extracted by Autobound

From the Signal API record
Event
Launch

What this signalsA launch often needs new go-to-market and support spend.

Product
Identity Services Engine

The full record

From the Signal API record

Details

Release type
Update

Topics and mentions

Product tags

  • security
  • online technology
  • general technology

Extraction

Confidence
90%
Detected
Sep 17, 2026
signal_type
news
signal_subtype
launches

Use this data

Get every launch signal for Cisco and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Cisco this week?”

  2. Send it to your own tools

    The Signal API returns launch signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/edad4799-f435-c529-b6f2-262544666d00 returns this record as JSON. POST /v1/companies/enrich returns every signal for cisco.com.

{
  "signal_id": "edad4799-f435-c529-b6f2-262544666d00",
  "signal_type": "news",
  "signal_subtype": "launches",
  "detected_at": "2026-09-17T12:40:00+00:00",
  "company": {
    "name": "Cisco",
    "domain": "cisco.com"
  },
  "data": {
    "url": "https://www.theregister.com/security/2026/09/17/cisco-drops-another-exploited-zero-day-this-time-a-perfect-10/5297180",
    "title": "Cisco drops another exploited zero-day, this time a perfect 10",
    "excerpt": "security ISE authentication bypass under active attack just days after another Cisco zero-day sent admins scrambling to patch Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack. Cisco disclosed CVE-2026-76460 on Wednesday , describing it as an authentication bypass affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Successful exploitation can give an unauthenticated remote attacker command execution with root privileges. Product Security Incident Response Team said it was aware of active exploitation and urged customers to install the fixes immediately. CISA has also added the vulnerability to its Known Exploited Vulnerabilities catalog . The warning follows another actively exploited critical vulnerability disclosed days earlier, CVE-2026-76461, affecting its Secure Email Gateway and Secure Email and Web Manager appliances. That 9.8-rated bug could also lead to root access, prompting Cisco to warn admins that attackers may be able to cover their tracks after getting in. The latest problem lies in an API within Cisco ISE, the company's network access control platform. Cisco says insufficient authentication controls on an API endpoint mean an attacker can send a crafted request to bypass the product's web-based management interface. No credentials or user...",
    "product": "Identity Services Engine",
    "summary": "Cisco has released security fixes for its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products to address a critical vulnerability.",
    "planning": false,
    "image_url": "https://image.theregister.com/5249134.jpg?imageId=5249134&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683",
    "confidence": 0.9,
    "product_data": {
      "name": "Identity Services Engine",
      "full_text": "ISE and ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4",
      "fuzzy_match": false,
      "release_type": "update"
    },
    "product_tags": [
      "security",
      "online_technology",
      "general_technology"
    ],
    "published_at": "2026-09-17T12:40:00Z",
    "article_sentence": "Permanent fixes are available in ISE and ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.