Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)
Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint that lets a remote unauthenticated attacker bypass the web management interface; the fix requires upgrading to 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4, and no workarounds exist. The Shadowserver Foundation separately observed active exploitation of CVE-2026-89026 in Issabel Framework, where a hard-coded HS256 JWT signing key in pbxapi/index.php lets an unauthenticated attacker forge bearer tokens and execute arbitrary OS commands as the Asterisk user; a patch shipped August 1, 2026, replaces the key with one stored in /etc/issabel.conf.
Read this edition