Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cisco ISE and ISE-PIC actively exploited authentication bypass (CVE-2026-76460)

Vulnerability
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

Cisco ISE and ISE-PIC are facing CVE-2026-76460, a maximum-severity API authentication bypass that is actively exploited in the wild. The flaw can let remote attackers send a crafted request and gain unauthorized access by bypassing the web-based management interface. Fixed software releases are available, and CISA has added the CVE to the KEV Catalog with a three-day patch deadline for federal agencies.

Related Happenings

Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog ordered federal agencies to patch systems against CVE-2026-76460 for within

Public Sector Action
H score36 First: 17.09.2026 10:20 Last: 17.09.2026 10:20 Sources 1

How related: The Cybersecurity and Infrastructure Security Agency (CISA) also ordered federal agencies to patch their systems against CVE-2026-76460 within three days after adding it to its Known Exploited Vulnerabilities (KEV) Catalog on Wednesday.

About this happening: CISA ordered federal agencies to patch CVE-2026-76460 within three days, imposing an urgent remediation deadline for an actively exploited Cisco flaw. The orde...

SharkLoader loader activity deploying Cobalt Strike Beacon

Malware Activity
H score30 First: 26.06.2026 21:17 Last: 26.06.2026 21:17 Sources 1

About this happening: A newly observed SharkLoader malware operation is staging Cobalt Strike Beacon on compromised Windows hosts, expanding post-compromise control and persistence risk. The lo...

StrikeShark SharkLoader and Cobalt Strike Beacon campaign

Campaign
H score42 First: 26.06.2026 21:17 Last: 26.06.2026 21:17 Sources 1

About this happening: The StrikeShark campaign is deploying SharkLoader to load Cobalt Strike Beacon on compromised hosts, raising the risk of broader follow-on intrusion activity. It has t...

BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances

Malware Activity
H score29 First: 18.02.2026 12:32 Last: 18.02.2026 12:32 Sources 1

About this happening: BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...

Timeline

  1. 17.09.2026 10:20 2 articles · 1h ago

    Cisco patches actively exploited CVE-2026-76460 in ISE and ISE-PIC

    Initial Disclosure

    Cisco released security updates for CVE-2026-76460 in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), a maximum-severity API authentication bypass that lets remote attackers send a crafted request to an affected API endpoint and gain unauthorized access by bypassing the web-based management interface. Cisco PSIRT said the vulnerability is actively exploited, shared indicators of compromise, advised checking access.log files and network/firewall logs, and recommended upgrading to a fixed software release because no workarounds exist. CISA added CVE-2026-76460 to the KEV Catalog and ordered federal agencies to patch within three days.

    Show sources