← Back

Wire · technology

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Published

17 September 2026

Topic

technology

◆ Sectors

Security: Cybersecurity

◆ Geography

United States

◆ Source

Read at thehackernews.com →

◆ Verified

Fusion42 · 17 September 2026 · Fusion42 review

Cisco disclosed a critical zero-day vulnerability in its Identity Services Engine (ISE) allowing unauthenticated remote attackers to bypass authentication, currently exploited in active attacks, with fixed patches released. The U.S. CISA mandated patch application by federal agencies within days, highlighting the severe immediate cybersecurity risk.

This Wire brief sits within Fusion42's coverage of Security: Cybersecurity, and 4 sources have reported it between 17 Sep 2026 and 18 Sep 2026.

◆ ◆ The Wire takeaway

You must prioritise rolling out Cisco patches now or risk attackers gaining root access through this zero-day. This vulnerability leaves unpatched ISE systems defenseless against active exploits targeting your network management.

◆ Coverage

4 sources · first reported 17 Sep 2026 · latest 18 Sep 2026

◆ Related on Wire

◆ Topics

Security: Cybersecurityciscozero-dayauthentication-bypasscybersecuritycisapatch