Another Cisco Zero-Day, Another Scramble
Cisco administrators barely had time to catch their breath before facing a second emergency this month. Just days after a separate actively exploited vulnerability in Cisco's Secure Email Gateway product had teams scrambling to patch, the company has disclosed a new zero-day, this time in its Identity Services Engine (ISE), and it comes with the highest possible severity rating a vulnerability can receive: a perfect CVSS score of 10.0.
A CVSS score of 10 means the flaw checks every box that makes a vulnerability dangerous. It's remotely exploitable, requires no special privileges or user interaction, and can lead to a complete compromise of the affected system. In this case, the flaw is an authentication bypass, meaning attackers who exploit it can potentially skip login requirements entirely and gain access to systems that ISE is supposed to protect.
Why an Authentication Bypass in ISE Is a Big Deal
Cisco Identity Services Engine is not a niche product. It's a network access control platform used by enterprises, universities, hospitals, and government agencies to decide who and what gets to connect to a network. ISE checks the identity of devices and users before granting them access, enforces security policies, and often integrates with other security tools across an organization.
When the system responsible for verifying identity can itself be bypassed, the consequences ripple outward. An attacker who defeats ISE's authentication controls could potentially move laterally across a network, reach sensitive systems, or exfiltrate data, all while appearing to be a legitimate, authenticated user. That's precisely why this flaw's perfect severity score isn't just a technical curiosity. It reflects a real and immediate risk to the organizations that rely on ISE to keep unauthorized users out.
Cisco has confirmed the vulnerability is already being exploited in the wild, which raises the stakes considerably. Unlike theoretical bugs that researchers discover before criminals do, this one is actively being used against real targets right now, giving defenders a narrow and urgent window to apply fixes before more networks are compromised.
A Pattern Worth Watching
This is not an isolated incident. The ISE flaw arrives on the heels of another actively exploited Cisco zero-day affecting the company's email security products, meaning Cisco customers have had to respond to two serious, exploited vulnerabilities in a short span of time. For IT and security teams already stretched thin, back-to-back zero-days in widely deployed enterprise products mean back-to-back emergency patch cycles, risk assessments, and incident response reviews.
The repeated targeting of Cisco infrastructure also underscores a broader trend: attackers increasingly focus on the network equipment and identity systems that sit at the center of enterprise environments, rather than just individual endpoints. A single flaw in a product like ISE can affect thousands of organizations simultaneously, making these vulnerabilities especially attractive to sophisticated threat actors looking for maximum impact from minimum effort.
What This Means For You
If you work in IT or security at an organization that uses Cisco ISE, this is not a vulnerability to leave in the patch backlog. Given the perfect severity score and confirmed active exploitation, treat this as an emergency-level fix rather than routine maintenance. Review Cisco's advisory for the affected versions, apply the patch as soon as it's available for your deployment, and check logs for signs of suspicious authentication activity that might indicate the flaw was already exploited before you patched.
For everyday users and remote workers, this story is a reminder that the security of the networks you connect to, whether at work, school, or on public Wi-Fi, depends on infrastructure you rarely see or think about. While you can't patch your employer's ISE deployment yourself, you can reduce your own exposure by encrypting your traffic and being cautious about the networks you trust. If you're working from a Mac and want to add a layer of protection to your own connection, our guide to setting up a VPN on Mac walks through the options available to you.
Actionable Takeaways
- Organizations running Cisco ISE should prioritize patching this vulnerability immediately given its perfect CVSS 10 rating and confirmed active exploitation.
- IT teams should review authentication logs for anomalies that could indicate the flaw was exploited prior to patching.
- Security teams should factor in that Cisco has now disclosed multiple actively exploited zero-days in close succession, warranting a broader review of exposed Cisco infrastructure.
- Individual users can't patch enterprise systems, but strengthening personal security practices, including using a VPN on personal devices, adds a layer of protection regardless of what happens at the network level.
The pace of these disclosures is a clear signal that attackers are actively hunting for weaknesses in the identity and access systems businesses depend on. Staying current on vendor advisories and applying patches quickly remains one of the simplest, most effective defenses available.




