decrypted · 17 september 2026 · vulnerabilities and patching · uk policy and law · ai and llm security
Cisco's network gatekeeper let attackers in without a login
Cisco confirmed this week that attackers are already exploiting a maximum-severity flaw in Identity Services Engine, the software many large organisations use to decide which devices and users are allowed onto their network. CVE-2026-76460 scores a perfect 10.0 on the CVSS scale, has no workaround, and Cisco's own advisory says the vulnerability affects every ISE configuration, not just badly set up ones. Patch it before anything else on your list tonight.
The gatekeeper's side door
ISE is the software that stands between a laptop or phone and the rest of the network: it checks who and what a device is before letting it in, often as the backbone of a Zero Trust policy. CVE-2026-76460 sits in an API endpoint that never got the same authentication checks as the front door. Cisco's advisory describes it plainly: a single crafted request to that endpoint bypasses the web-based management interface entirely, no valid credentials needed. From there, exploitation can reach command execution as root, meaning an attacker with a foothold can also erase the very logs that would show they were ever inside. Cisco has confirmed active exploitation, and CISA gave US federal agencies until 19 September to patch after adding it to its Known Exploited Vulnerabilities catalogue. Fixes are out now, from 3.1 Patch 12 through 3.5 Patch 4. With no workaround beyond restricting network access to the appliance while you patch, the only real option is to move quickly.
The Secure by Design lesson
The interesting failure here isn't cryptographic, it's architectural. Somewhere in ISE, a second route into the same privileged functionality as the management login existed without the login's controls attached to it. That pattern turns up again and again: a product gets its primary interface locked down properly, while a secondary API serving the same underlying functions quietly ships with weaker checks, because nobody treated it as an equally sensitive front door. Secure by Design means applying authentication consistently across every interface that reaches privileged functions, not just the one a pen test happened to point at. For UK organisations running ISE, the task tonight is narrower: find every deployment, patch it, and check access logs for anomalous requests to the affected endpoint, since a clean-looking box may already have had its evidence quietly wiped.
Also this week
Ofcom's fines are easier to issue than to collect. The regulator has levied more than £7 million in Online Safety Act penalties against 11 providers, but enforcement director Suzanne Cater told The Register this week that "realistically the majority have not been paid," largely because offending platforms hold no UK assets to seize. Ofcom says it is starting to pursue senior managers personally and is exploring stronger collection powers with government. A penalty regime only has teeth if it was designed, from the outset, around who is actually reachable, and this one wasn't.
The row over Anthropic and the UK's AI Security Institute escalated in Parliament. Anthropic released its restricted Claude Mythos 5.1 model on 1 September without giving the government-backed AI Security Institute pre-release access, unlike comparable US evaluators, first reported by the Financial Times. This week Liam Byrne, who chairs the Commons Business and Trade Committee, wrote to the institute questioning Britain's role in frontier AI evaluation and summoned its director to give evidence on 13 October, alongside a former Anthropic researcher who quit warning that developers were "racing straight to self-improving superintelligence." Whatever the merits of that warning, the access question stands on its own: a safety institute that only gets to test the models a vendor chooses to show it isn't really testing anything.
Thales launched a UK-hosted cloud HSM this week, letting organisations generate, store and destroy their cryptographic keys entirely within UK borders even when the application sits in someone else's cloud. It's a useful, narrow reminder: data residency and key sovereignty are not the same promise. A US-owned cloud provider hosting your data in London does not, by itself, put your encryption keys beyond the reach of the US CLOUD Act.
Sources
- Cisco Security Advisory: Cisco Identity Services Engine Authentication Bypass Vulnerability
- Cisco warns of max severity ISE zero-day exploited in attacks
- Ofcom discovers issuing Online Safety Act fines is easier than collecting them
- Anthropic reportedly withholds access to Mythos 5.1 from UK safety testing body
- Former Anthropic researcher behind 'AI could kill us' warning called to UK parliament
- From data residency to key sovereignty: Thales launches UK cloud HSM
If you want a second pair of eyes on your Secure by Design posture, get in touch.
More like this
- A crafted email is all it takes to root Cisco's mail gateway 15 september 2026
- The AI test that broke into a real company because it couldn't stop 11 september 2026
- A default password was the only thing standing between the internet and 220 million passports 9 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.