ZeroHour

Search: “ips”

3 stories in the last 24h

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)new

Cisco confirmed CVE-2026-76460, an actively exploited unauthenticated authentication bypass in Cisco ISE APIs, urging immediate patching with no workarounds available.

Cisco confirmed active exploitation of CVE-2026-76460, caused by insufficient authentication control on an ISE API endpoint. A remote, unauthenticated attacker can send a crafted request to bypass the web-based management interface and gain unauthorized access to affected devices. The flaw affects Cisco ISE and ISE-PIC releases 3.0 through 3.5; fixes are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4, with no workarounds. Cisco provided IoCs, advises checking access.log for suspicious usernames, cross-checking firewall and network logs, and re-imaging suspect nodes since attackers may delete ISE logs.

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco patched CVE-2026-76460, a maximum-severity authentication bypass in Identity Services Engine actively exploited in attacks; CISA added it to KEV with a three-day federal deadline.

CVE-2026-76460 is a maximum-severity authentication bypass in an API endpoint of Cisco Identity Services Engine (ISE) and ISE-PIC, exploitable regardless of configuration, allowing attackers to access the web-based management interface. Cisco PSIRT confirmed active exploitation; no workarounds exist, and fixed releases are available for ISE 3.1 through 3.5, with re-imaging of suspect nodes recommended. CISA added the flaw to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch within three days. Cisco also patched CVE-2026-76423 and five other critical ISE flaws (CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, CVE-2026-20284) that are not yet flagged as exploited.

BleepingComputer · 3h agoExploit / PoC in the wildCVE-2026-76460CVE-2026-76423CVE-2026-20176+4 CVEs1· 1 read

Critical Issabel PBX Command Execution Vulnerability Exploited in the Wild

Unauthenticated attackers exploit CVE-2026-89026 in Issabel PBX via forged JWT tokens to run OS commands; exploitation observed since September 9.

CVE-2026-89026 (CVSS v4 9.3) stems from a hard-coded HS256 JWT signing key in Issabel Framework's pbxapi/index.php, letting unauthenticated attackers forge bearer tokens and execute OS commands through the Asterisk Manager Interface originate endpoint. Issabel Framework versions before commit b97dbaf0b71c1c36f841e672b664afbeb02773bd are affected. Shadowserver Foundation first observed exploitation on September 9, 2026, and VulnCheck added the flaw to its Known Exploited Vulnerabilities database.

Cyber Security Newsupdated · 18h agofirst · 21h agoExploit / PoC in the wild 2 sourcesCVE-2026-890261