Cisco ISE and ISE-PIC actively exploited authentication bypass (CVE-2026-76460)
Vulnerability
Summary
Hide ▲
Show ▼
Cisco ISE and ISE-PIC are facing CVE-2026-76460, a maximum-severity API authentication bypass that is actively exploited in the wild. The flaw can let remote attackers send a crafted request and gain unauthorized access by bypassing the web-based management interface. Fixed software releases are available, and CISA has added the CVE to the KEV Catalog with a three-day patch deadline for federal agencies.
Related Happenings
Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog ordered federal agencies to patch systems against CVE-2026-76460 for within
Public Sector Action
H score36
First: 17.09.2026 10:20
Last: 17.09.2026 10:20
Sources 1
How related:
The Cybersecurity and Infrastructure Security Agency (CISA) also ordered federal agencies to patch their systems against CVE-2026-76460 within three days after adding it to its Known Exploited Vulnerabilities (KEV) Catalog on Wednesday.
About this happening:
CISA ordered federal agencies to patch CVE-2026-76460 within three days, imposing an urgent remediation deadline for an actively exploited Cisco flaw. The orde...
Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog ordered federal agencies to patch systems against CVE-2026-76460 for within
Public Sector ActionHow related: The Cybersecurity and Infrastructure Security Agency (CISA) also ordered federal agencies to patch their systems against CVE-2026-76460 within three days after adding it to its Known Exploited Vulnerabilities (KEV) Catalog on Wednesday.
About this happening: CISA ordered federal agencies to patch CVE-2026-76460 within three days, imposing an urgent remediation deadline for an actively exploited Cisco flaw. The orde...
SharkLoader loader activity deploying Cobalt Strike Beacon
Malware Activity
H score30
First: 26.06.2026 21:17
Last: 26.06.2026 21:17
Sources 1
About this happening:
A newly observed SharkLoader malware operation is staging Cobalt Strike Beacon on compromised Windows hosts, expanding post-compromise control and persistence risk. The lo...
SharkLoader loader activity deploying Cobalt Strike Beacon
Malware ActivityAbout this happening: A newly observed SharkLoader malware operation is staging Cobalt Strike Beacon on compromised Windows hosts, expanding post-compromise control and persistence risk. The lo...
StrikeShark SharkLoader and Cobalt Strike Beacon campaign
Campaign
H score42
First: 26.06.2026 21:17
Last: 26.06.2026 21:17
Sources 1
About this happening:
The StrikeShark campaign is deploying SharkLoader to load Cobalt Strike Beacon on compromised hosts, raising the risk of broader follow-on intrusion activity. It has t...
StrikeShark SharkLoader and Cobalt Strike Beacon campaign
CampaignAbout this happening: The StrikeShark campaign is deploying SharkLoader to load Cobalt Strike Beacon on compromised hosts, raising the risk of broader follow-on intrusion activity. It has t...
BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances
Malware Activity
H score29
First: 18.02.2026 12:32
Last: 18.02.2026 12:32
Sources 1
About this happening:
BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...
BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances
Malware ActivityAbout this happening: BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...
Timeline
-
17.09.2026 10:20 2 articles · 1h ago
Cisco patches actively exploited CVE-2026-76460 in ISE and ISE-PIC
Initial DisclosureCisco released security updates for CVE-2026-76460 in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), a maximum-severity API authentication bypass that lets remote attackers send a crafted request to an affected API endpoint and gain unauthorized access by bypassing the web-based management interface. Cisco PSIRT said the vulnerability is actively exploited, shared indicators of compromise, advised checking access.log files and network/firewall logs, and recommended upgrading to a fixed software release because no workarounds exist. CISA added CVE-2026-76460 to the KEV Catalog and ordered federal agencies to patch within three days.
Show sources
- Cisco warns of max severity ISE zero-day exploited in attacks — www.bleepingcomputer.com — 17.09.2026 10:20
- Cisco warns of max severity ISE zero-day exploited in attacks — www.bleepingcomputer.com — 17.09.2026 10:20