← Back to Feed
Cisco warns of max severity ISE zero-day exploited in attacks
September 17, 2026 · BleepingComputer · Severity: CRITICAL
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild.
Key Takeaways
- Cisco patched a maximum-severity zero-day vulnerability in Identity Services Engine that attackers are actively exploiting in the wild against unpatched deployments.
- The critical ISE flaw carries the highest CVSS severity rating, reflecting its potential to compromise network access control and authentication infrastructure enterprise-wide.
- Organizations running Cisco ISE should immediately apply available security updates since active exploitation indicates working exploits are already in circulation.