Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog ordered federal agencies to patch systems against CVE-2026-76460 for within
Public Sector Action
Summary
Hide ▲
Show ▼
CISA ordered federal agencies to patch CVE-2026-76460 within three days, imposing an urgent remediation deadline for an actively exploited Cisco flaw. The order followed the agency's addition of the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on Wednesday. The directive forces rapid mitigation across the federal civilian environment because the flaw allows remote attackers to bypass authentication in Cisco ISE and ISE-PIC.
Related Happenings
Cisco ISE and ISE-PIC actively exploited authentication bypass (CVE-2026-76460)
Vulnerability
H score34
First: 17.09.2026 10:20
Last: 17.09.2026 10:20
Sources 1
How related:
The security flaw (tracked as CVE-2026-76460) lets remote attackers bypass authentication by exploiting a weakness in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of configuration.
About this happening:
Cisco ISE and ISE-PIC are facing CVE-2026-76460, a maximum-severity API authentication bypass that is actively exploited in the wild. The flaw can let remote attac...
Cisco ISE and ISE-PIC actively exploited authentication bypass (CVE-2026-76460)
VulnerabilityHow related: The security flaw (tracked as CVE-2026-76460) lets remote attackers bypass authentication by exploiting a weakness in an API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of configuration.
About this happening: Cisco ISE and ISE-PIC are facing CVE-2026-76460, a maximum-severity API authentication bypass that is actively exploited in the wild. The flaw can let remote attac...
Cisco Secure FMC static credential flaw actively exploited (CVE-2026-20316)
Vulnerability
H score51
First: 30.07.2026 00:35
Last: 30.07.2026 00:35
Sources 1
About this happening:
Cisco Secure Firewall Management Center (FMC) is under active exploitation through CVE-2026-20316 and CVE-2026-20079, with Cisco Talos linking the activity to th...
Cisco Secure FMC static credential flaw actively exploited (CVE-2026-20316)
VulnerabilityAbout this happening: Cisco Secure Firewall Management Center (FMC) is under active exploitation through CVE-2026-20316 and CVE-2026-20079, with Cisco Talos linking the activity to th...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector Action
H score27
First: 10.06.2026 15:00
Last: 10.06.2026 15:00
Sources 1
About this happening:
CISA issued Binding Operational Directive 26-04 for federal civilian agencies, directing them to prioritize vulnerability remediation using Asset Exposure, KEV S...
CISA BOD 26-04 prioritizes vulnerability remediation for federal civilian agencies
Public Sector ActionAbout this happening: CISA issued Binding Operational Directive 26-04 for federal civilian agencies, directing them to prioritize vulnerability remediation using Asset Exposure, KEV S...
CISA launches KEV Nomination Form
Public Sector Action
H score38
First: 21.05.2026 15:00
Last: 21.05.2026 15:00
Sources 1
About this happening:
CISA launched a new Nomination Form for the KEV catalog, giving researchers, vendors, and industry partners a direct way to report known exploited vulnerabilities....
CISA launches KEV Nomination Form
Public Sector ActionAbout this happening: CISA launched a new Nomination Form for the KEV catalog, giving researchers, vendors, and industry partners a direct way to report known exploited vulnerabilities....
CISA KEV order for Copy Fail on federal Linux devices
Public Sector Action
H score33
First: 08.05.2026 10:45
Last: 08.05.2026 10:45
Sources 1
About this happening:
CISA added Copy Fail to the Known Exploited Vulnerabilities (KEV) Catalog, making the Linux flaw a federal remediation priority. The agency ordered federal agencies*...
CISA KEV order for Copy Fail on federal Linux devices
Public Sector ActionAbout this happening: CISA added Copy Fail to the Known Exploited Vulnerabilities (KEV) Catalog, making the Linux flaw a federal remediation priority. The agency ordered federal agencies*...
Timeline
-
17.09.2026 10:20 2 articles · 1h ago
CISA orders federal agencies to patch CVE-2026-76460 within three days
Legal Policy Action UpdateCISA added CVE-2026-76460 to the Known Exploited Vulnerabilities (KEV) Catalog and ordered federal agencies to patch their systems within three days after Cisco said the Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC) authentication-bypass flaw was actively exploited.
Show sources
- Cisco warns of max severity ISE zero-day exploited in attacks — www.bleepingcomputer.com — 17.09.2026 10:20
- Cisco warns of max severity ISE zero-day exploited in attacks — www.bleepingcomputer.com — 17.09.2026 10:20
-
17.09.2026 10:20 1 articles · 1h ago
Cisco releases fixes for the actively exploited Cisco ISE authentication bypass
Mitigation Patch UpdateCisco released security updates for CVE-2026-76460 in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), warned that the flaw was actively exploited in the wild, said no workarounds exist, listed fixed releases for 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4, and shared indicators of compromise with advice to inspect access.log files and re-image suspected nodes.
Show sources
- Cisco warns of max severity ISE zero-day exploited in attacks — www.bleepingcomputer.com — 17.09.2026 10:20