Cisco Warns of Maximum-Severity ISE Zero-Day Actively Exploited in Attacks
Cisco releases emergency security updates for Identity Services Engine vulnerability under active exploitation; immediate patching urged.

Key Takeaways
- Cisco has released security updates for a maximum-severity ISE vulnerability that is being actively exploited.
- The vulnerability affects Cisco Identity Services Engine, a critical component for network access control.
- No CVE ID has been disclosed yet, but the flaw is confirmed as actively exploited in the wild.
- Immediate patching is strongly recommended; organizations should also monitor for indicators of compromise.
- Cisco has not yet provided technical details on the attack vector or impact.
Quick answers
- What happened?
- Cisco has released security updates to address a maximum-severity vulnerability in its Identity Services Engine (ISE) that is being actively exploited in the wild. The flaw, which has not yet been assigned a CVE ID, poses a critical risk to organizations using ISE for network access control and policy enforcement. Cisco urges administrators to apply the patches immediately to mitigate potential compromise.
- Which products are affected?
- Identity Services Engine
- What should defenders do?
- Apply the security updates provided by Cisco immediately. If patching is not possible, implement workarounds as recommended by Cisco and enhance monitoring for suspicious activity. Review network logs for indicators of compromise and consider segmenting ISE from critical systems until patched.
Cisco has issued an urgent security advisory warning of a maximum-severity vulnerability in its Identity Services Engine (ISE) that is currently being exploited in active attacks. The company has released software updates to remediate the flaw, which affects ISE deployments globally. While the specific CVE identifier has not been disclosed in the initial report, the advisory marks the issue as critical and confirms that exploitation is occurring in the wild.
The Identity Services Engine is a core component in many enterprise networks, providing centralized policy management, authentication, and authorization for network access. A vulnerability of this severity could allow an attacker to compromise the ISE appliance, potentially leading to unauthorized network access, lateral movement, or disruption of security controls.
Cisco has not yet provided technical details on the attack vector or the exact impact of the vulnerability, but the active exploitation suggests that threat actors have already developed working exploits. The company is urging all customers running affected versions of ISE to apply the available security updates as soon as possible.
Organizations that cannot immediately patch should consider implementing workarounds or additional monitoring to detect signs of compromise. Given the critical nature of the flaw and its active exploitation, prompt action is essential to protect network infrastructure.
Security Details
Cisco has released security updates to address a maximum-severity vulnerability in Identity Services Engine (ISE) that is being actively exploited in the wild. The specific CVE ID has not been disclosed, and technical details on the attack vector and impact are not yet available. The vulnerability is confirmed as actively exploited, indicating a high risk to affected organizations.
Affected products
Identity Services Engine
Mitigation
Apply the security updates provided by Cisco immediately. If patching is not possible, implement workarounds as recommended by Cisco and enhance monitoring for suspicious activity. Review network logs for indicators of compromise and consider segmenting ISE from critical systems until patched.
Sources
BleepingComputer
Cisco warns of max severity ISE zero-day exploited in attacks
Sep 17, 2026 · 07:20
Original link
Related Security News

Hackers exploit Citrix NetScaler zero-day to deploy web shells
Cybersecurity firms report that attackers are exploiting a zero-day vulnerability in Citrix NetScaler to deploy custom web shells and tunneling malware. The exploitation grants root access, enables credential theft, and facilitates lateral movement into internal networks. Citrix has released patches and security advisories addressing CVE-2026-88772.




