TechRadar News.
Security

Cisco ISE Zero‑Day Earns Full 10 CVSS Score, Reveals API Authentication Weakness

Cisco ISE Zero‑Day Earns Full 10 CVSS Score, Reveals API Authentication Weakness

Cisco's Identity Services Engine (ISE) is confronting a critical security flaw after a newly revealed zero‑day vulnerability, identified as CVE‑2026‑76460, received a flawless 10.0 rating on the CVSS scale, signifying the maximum possible threat to impacted deployments.

The defect lies in an API endpoint that does not enforce adequate authentication, permitting an unauthenticated actor to call privileged ISE functions. By leveraging this gap, an attacker can circumvent the platform's standard access‑control mechanisms and potentially obtain administrative rights without valid credentials.

ISE serves as a foundational component for many enterprise networks, delivering centralized authentication, authorization, and accounting for wired, wireless, and VPN traffic. Exploitation of this nature could enable malicious parties to alter network policies, spawn unauthorized user accounts, or exfiltrate sensitive authentication information, thereby facilitating lateral movement within the corporate environment.

The issue was uncovered by a security researcher who notified Cisco prior to public disclosure. Dark Reading was the first publication to cover the story, highlighting the swift progression from discovery to announcement. Cisco reacted by issuing an emergency advisory and publishing a patch that corrects the flawed API logic, urging customers to install the update promptly.

Security teams are being advised to prioritize the patch, confirm that all ISE instances run the newest firmware, and scrutinize audit logs for any indications of unauthorized API activity. Additional best‑practice measures include tightening network segmentation, implementing multi‑factor authentication for administrative access, and performing regular penetration testing focused on API surfaces.

This incident underscores a growing pattern of attackers targeting the increasingly programmable interfaces of networking gear. As organizations depend on APIs to automate policy enforcement and integrate third‑party solutions, robust authentication and authorization safeguards become crucial to avert comparable high‑impact exploits in the future.

TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related