SECURITY·중요도 10·2026. 09. 17.·The Hacker News
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
── KO ──────────────────
시스코, ISE에서 새로운 제로데이 취약점 경고.
시스코가 아이덴티티 서비스 엔진(ISE)에 영향을 미치는 새로운 최대 심각도 보안 결함에 대해 경고했습니다. 이 취약점(CVE-2026-76460)은 인증되지 않은 원격 공격자가 인증 우회를 허용할 수 있으며, CVSS 점수는 10.0입니다. 시스코는 이 취약점이 API 엔드포인트의 인증 제어 부족으로 인한 것이라고 밝혔습니다.
── EN ──────────────────
Cisco warns of a new zero-day vulnerability in ISE.
Cisco has issued a warning about a new maximum-severity security vulnerability affecting the Identity Services Engine (ISE). This vulnerability, tracked as CVE-2026-76460 with a CVSS score of 10.0, could allow an unauthenticated, remote attacker to bypass authentication. Cisco stated that this issue arises from insufficient authentication control on an API endpoint.