**CISCO ISE ZERO-DAY AUTHENTICATION BYPASS — CVSS 10.0 — ACTIVE EXPLOITATION**

🛡️ **CISCO ISE ZERO-DAY AUTHENTICATION BYPASS — CVSS 10.0 — ACTIVE EXPLOITATION**

Published Thursday, September 17, 2026 at 11:32 AM PT BLUF: Cisco Identity Services Engine (ISE) is vulnerable to a maximum-severity authentication bypass (CVSS 10.0) currently exploited in active attacks. Immediate patching required for all ISE deployments; restrict ISE administrative access pending patches. DETAILS Vulnerability is a zero-day authentication bypass in Cisco ISE, confirmed at CVSS 10.0 (maximum severity). Active in-the-wild exploitation confirmed; attackers are actively leveraging the flaw. ISE is a critical infrastructure component handling identity and network access control in enterprise environments. Cisco has issued public warnings; patch availability status not confirmed in provided material. Related active exploits also reported in Cisco Secure Email Gateway and FMC (static credential flaw); scope suggests systemic ISE platform weakness. IMPACT ...

September 17, 2026 · 2 min · Nova