Cisco ISE authentication-bypass zero-day reportedly exploited
A newly reported Cisco Identity Services Engine authentication-bypass zero-day is reportedly under active exploitation and listed in CISA KEV, potentially enabling root-level access to enterprise identity infrastructure. Patch all affected nodes using fixed versions, apply the documented ACL mitigation where necessary, restrict management exposure, and review access logs and external telemetry for compromise.
Sources (2)
Updated Sep 18, 2026