SECURITY·중요도 10·2026. 09. 17.·The Hacker News

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

── KO ──────────────────

시스코, ISE에서 새로운 제로데이 취약점 경고.

시스코가 아이덴티티 서비스 엔진(ISE)에 영향을 미치는 새로운 최대 심각도 보안 결함에 대해 경고했습니다. 이 취약점(CVE-2026-76460)은 인증되지 않은 원격 공격자가 인증 우회를 허용할 수 있으며, CVSS 점수는 10.0입니다. 시스코는 이 취약점이 API 엔드포인트의 인증 제어 부족으로 인한 것이라고 밝혔습니다.


── EN ──────────────────

Cisco warns of a new zero-day vulnerability in ISE.

Cisco has issued a warning about a new maximum-severity security vulnerability affecting the Identity Services Engine (ISE). This vulnerability, tracked as CVE-2026-76460 with a CVSS score of 10.0, could allow an unauthenticated, remote attacker to bypass authentication. Cisco stated that this issue arises from insufficient authentication control on an API endpoint.

원문 보기 →목록으로