Cisco security patch release for CVE-2026-76460
Security Patch Release
Summary
Hide ▲
Show ▼
Cisco released security updates for Cisco ISE and ISE-PIC to fix CVE-2026-76460, a maximum-severity authentication bypass that is actively exploited in the wild. The fixed releases are the only recommended remediation because no workarounds exist. The patch bundle covers the affected ISE software lines and closes a flaw that can expose management access to remote attackers.
Related Happenings
ThemeFusion security patch release for CVE-2026-18431
Security Patch Release
H score43
First: 27.08.2026 00:33
Last: 27.08.2026 00:33
Sources 1
About this happening:
ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
ThemeFusion security patch release for CVE-2026-18431
Security Patch ReleaseAbout this happening: ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
Adobe security patch release for CVE-2026-48362
Security Patch Release
H score43
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-48362
Security Patch ReleaseAbout this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Cisco security patch release for CVE-2026-20337
Security Patch Release
H score30
First: 11.08.2026 14:03
Last: 11.08.2026 14:03
Sources 1
About this happening:
Cisco released ClamAV 1.5.4 to fix CVE-2026-20337 and CVE-2026-20338, reducing denial-of-service risk for deployments running ClamAV 1.5.0 through 1.5.3. T...
Cisco security patch release for CVE-2026-20337
Security Patch ReleaseAbout this happening: Cisco released ClamAV 1.5.4 to fix CVE-2026-20337 and CVE-2026-20338, reducing denial-of-service risk for deployments running ClamAV 1.5.0 through 1.5.3. T...
Cisco security patch release for CVE-2026-20303
Security Patch Release
H score43
First: 06.08.2026 20:13
Last: 06.08.2026 20:13
Sources 1
About this happening:
Cisco rolled out updates for Cisco Catalyst SD-WAN Software to fix five critical CVEs across affected releases, including CVE-2026-20303 and CVE-2026-20304. Th...
Cisco security patch release for CVE-2026-20303
Security Patch ReleaseAbout this happening: Cisco rolled out updates for Cisco Catalyst SD-WAN Software to fix five critical CVEs across affected releases, including CVE-2026-20303 and CVE-2026-20304. Th...
Dify security patch release for CVE-2026-41947
Security Patch Release
H score34
First: 22.06.2026 19:13
Last: 22.06.2026 19:13
Sources 1
About this happening:
Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...
Dify security patch release for CVE-2026-41947
Security Patch ReleaseAbout this happening: Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...
Timeline
-
17.09.2026 10:20 2 articles · 1h ago
Cisco releases fixes for actively exploited Cisco ISE authentication bypass
Mitigation Patch UpdateCisco released security updates for CVE-2026-76460 in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) after identifying a maximum-severity authentication bypass that remote attackers can trigger with a crafted request to an affected API endpoint. Cisco said PSIRT was aware of active exploitation, noted that no workarounds exist, listed fixed releases for the affected 3.1 through 3.5 branches, and advised immediate upgrading; CISA also added the CVE to its KEV Catalog and ordered federal agencies to patch within three days.
Show sources
- Cisco warns of max severity ISE zero-day exploited in attacks — www.bleepingcomputer.com — 17.09.2026 10:20
- Cisco warns of max severity ISE zero-day exploited in attacks — www.bleepingcomputer.com — 17.09.2026 10:20