Wire · technology
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 17 September 2026 · Fusion42 review
Cisco disclosed a critical zero-day vulnerability in its Identity Services Engine (ISE) allowing unauthenticated remote attackers to bypass authentication, currently exploited in active attacks, with fixed patches released. The U.S. CISA mandated patch application by federal agencies within days, highlighting the severe immediate cybersecurity risk.
This Wire brief sits within Fusion42's coverage of Security: Cybersecurity, and 4 sources have reported it between 17 Sep 2026 and 18 Sep 2026.
◆ ◆ The Wire takeaway
You must prioritise rolling out Cisco patches now or risk attackers gaining root access through this zero-day. This vulnerability leaves unpatched ISE systems defenseless against active exploits targeting your network management.
◆ Coverage
4 sources · first reported 17 Sep 2026 · latest 18 Sep 2026
◆ Related on Wire
◆ Topics