:

CISCO PATCHES MAX-SEVERITY ISE ZERO-DAY UNDER ACTIVE ATTACK

SECURITY DESK2 MIN READ
THU, SEP 17, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Cisco has released security updates for a critical Identity Services Engine vulnerability being actively exploited by attackers. The zero-day flaw carries a CVSS score of 10.0, indicating maximum severity.

Cisco disclosed the vulnerability in its Identity Services Engine (ISE) platform, which manages network access and authentication across enterprise environments. The company confirmed that threat actors are exploiting the flaw in live attacks. The vulnerability allows unauthenticated attackers to execute arbitrary code and gain complete system control. ISE deployments worldwide face immediate risk, making patching a priority for organizations relying on the platform for network security. Cisco urged customers to apply patches without delay. The company provided updates across multiple ISE versions. Administrators should verify their current version and deploy the appropriate fix from Cisco's security advisory. Identity Services Engine is a widely-used platform in enterprise networks, handling critical authentication and authorization functions. A compromise could grant attackers deep access to protected infrastructure and sensitive systems. The zero-day's active exploitation in the wild underscores the urgent threat level. Security researchers tracking the campaign have not disclosed specific attack methods, but organizations should assume threat actors possess working exploits. Cisco recommended customers apply fixes immediately and monitor ISE systems for suspicious activity. Network teams should review access logs for unauthorized authentication attempts and unusual administrative access. Organizations unable to patch immediately should consider isolating vulnerable instances or implementing network-based protections. The disclosure follows a pattern of critical vulnerabilities in authentication and network access platforms becoming prime targets for attackers seeking footholds in enterprise networks. ISE's role in controlling network access makes it particularly valuable to threat actors aiming for persistent access.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Chinese espionage group FamousSparrow is using a new backdoor malware called SparroWocky to target government organizations across Latin America.

JUST NOWSecurity Desk

A reverse-engineering enthusiast has successfully broken Sony's original PlayStation 2 security chip after four years of effort. The CXP102064 MechaCon chip, which protected the console from unauthorized software, has been fully unlocked.

JUST NOWSecurity Desk

A security researcher has successfully recovered the cryptographic signing keys used to secure barcodes on US driver's licenses. The discovery exposes a potential vulnerability in state ID verification systems nationwide.

2H AGOIndustry Desk

The Port of Los Angeles, America's busiest container port, deflected over 120 million cyberattack attempts last month. The volume underscores mounting security threats facing critical U.S. infrastructure amid operational pressures from changing trade policies.

2H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.