Cisco releases security updates to address a maximum-severity zero-day vulnerability in its Identity Services Engine (ISE). Multiple outlets report that attackers are already exploiting the flaw in the wild, prompting Cisco to urge organizations to apply the available patches.

TechRadar adds that U.S. authorities are also warning defenders, stating that CISA has issued advisories aligned with Cisco’s assessment. While the reports focus on urgent remediation, they do not broadly diverge on the core details: the product affected is Cisco ISE, the severity is the highest tier Cisco assigns, and the activity is ongoing rather than theoretical.

Both sources frame the incident as part of a coordinated response between the vendor and security agencies, with the central operational message centered on patching and mitigation to reduce exposure.