Cisco's Zero-Day Is Being Exploited Right Now. What Does That Mean for Your Business?
Two stories broke within hours of each other yesterday. Both scored CVSS 10.0. One is being actively exploited. Neither is getting the attention it deserves from the people who actually need to act on it.
Pull up a chair.
Story One: Cisco’s Network Access Product Has a Zero-Day Under Active Attack
Cisco has disclosed CVE-2026-76460, a maximum-severity authentication bypass in its Identity Services Engine (ISE). CVSS score: 10.0. Status: actively exploited in the wild, confirmed by CISA.
Let’s be precise about what Cisco ISE actually is, because this matters. ISE is the product enterprises and managed service providers use to control which devices and users are allowed onto a network. It is the gatekeeper. An authentication bypass in the gatekeeper means an attacker can walk straight past it, without needing a valid credential, without triggering the usual access controls, and with the potential for root command execution on the device itself.
This is not a theoretical risk. CISA confirmed active exploitation. That means real attackers are running this against real targets, right now.
A separate Cisco vulnerability, CVE-2026-76461, affecting Cisco Secure Email Gateway, has also entered CISA’s Known Exploited Vulnerabilities catalogue. If your email security is handled by a provider running Cisco’s email platform, that is a second active exposure.
Patches exist for both. The question is whether your provider has applied them.
Story Two: Microsoft Azure Had a Very Bad Night
Overnight, Microsoft published a cluster of CVSS 10.0 vulnerabilities affecting Azure infrastructure. The list includes:
- CVE-2026-69399: Azure Arc elevation of privilege
- CVE-2026-70200 and CVE-2026-83944: Azure Logic Apps, two separate privilege escalation and path traversal flaws
- CVE-2026-85889: Azure AI Foundry, missing authentication for a critical function
- CVE-2026-62874: Azure Billing, insufficient verification allowing privilege escalation
- CVE-2026-69843: Microsoft Fabric, authentication bypass by spoofing
- CVE-2026-69865: Microsoft Container Registry, authorisation bypass via user-controlled key
To be direct: these are cloud platform vulnerabilities. Most of them allow an unauthenticated attacker to elevate privileges over a network. Some do not require any user interaction. None of these have appeared in CISA’s KEV catalogue yet, which means active exploitation has not been confirmed as of this writing. But CVSS 10.0 ratings on cloud infrastructure components are not assigned casually.
If your business uses Azure, Microsoft 365, or any service built on Azure infrastructure, you are dependent on Microsoft applying these patches correctly and promptly. That is largely out of your hands. What is in your hands is knowing this is happening and asking the right questions.
Why This Matters If You Are Not Running Enterprise Cisco or Azure Directly
The obvious objection: “We are a twelve-person accountancy practice. We do not run Cisco ISE. This does not apply to us.”
The data says otherwise. Three vectors of exposure apply here.
First: your MSP. Managed service providers routinely use Cisco infrastructure to manage client networks. The same ISE installation that controls access for your provider’s internal systems may also govern the privileged access they use to manage yours. If their ISE is compromised, the attacker has a foothold in the provider’s tooling, and from there the path to your environment is shorter than you would like.
Second: your supply chain. Your accountant has clients in logistics. Your solicitor has clients in healthcare. The Cisco ISE zero-day is not targeted at small businesses directly. It is targeted at the network access control layer that larger organisations and their service providers use. When those organisations are compromised, the lateral movement often goes through their supplier relationships.
Third: your cloud dependencies. The Azure vulnerabilities are unpatched at time of writing. If your business runs on Microsoft 365, Azure Virtual Desktop, or any SaaS product hosted on Azure infrastructure, you have a dependency on Microsoft’s response speed. That is not a reason to panic. It is a reason to know.
What the Data Actually Shows (Versus What Vendors Will Tell You)
Vendors will frame this week as evidence that you need more products. That framing is usually wrong.
What the data shows is a failure at the foundational layer: network access control and cloud platform authorisation. The defences that should prevent an attacker from getting in at all are the ones with the holes in them this week.
For small businesses, the actionable signal is not “buy a new tool”. It is: verify that the people responsible for your infrastructure have patched the things that are currently being exploited. That is a conversation, not a purchase.
The Cisco ISE patch is available. If your MSP has not applied it, ask them when they plan to. If they cannot give you a specific date, that tells you something about the quality of their vulnerability management practice.
Why Being Informed Gives You a Real Advantage
Most of your competitors’ directors will not have heard of CVE-2026-76460 by Monday morning. Most will not have asked their IT providers whether their network access control systems are patched against an actively exploited zero-day.
Being the business owner who did ask, and who has documented the response, puts you in a materially different position on two fronts.
First: you have genuine evidence of due diligence if something does go wrong downstream. The ICO takes a dim view of organisations that cannot demonstrate they were monitoring known threats. “We were not aware” is a progressively harder position to defend when advisories are publicly issued and CISA publishes its KEV catalogue in real time.
Second: if you hold Cyber Essentials or are working towards it, demonstrating that your organisation tracks actively exploited vulnerabilities and follows up with suppliers is exactly the kind of governance that separates genuine security posture from checkbox compliance. Assessors notice the difference.
Making the Business Case
Three arguments for getting this in front of whoever holds the budget and signs off on IT decisions.
The risk is confirmed, not theoretical. CVE-2026-76460 is in CISA’s Known Exploited Vulnerabilities catalogue. That designation means CISA has confirmed real-world exploitation by real attackers. This is not a vendor projecting future risk to sell product. It is a government agency confirming current exploitation.
The cost of asking is zero. The question to your MSP costs nothing: “Have you applied the patch for CVE-2026-76460 on any Cisco ISE infrastructure you manage?” If the answer is yes, you have documented your due diligence. If the answer is no, you have identified a gap before it becomes a breach notification.
The ICO will ask. Under UK GDPR, organisations are expected to take appropriate technical and organisational measures to protect personal data. Following up on actively exploited critical vulnerabilities that affect your supply chain is not gold-plating. It is the baseline. Document that you asked and what the answer was.
What to Do Before the End of the Week
-
Contact your MSP today. Ask specifically whether they use Cisco Identity Services Engine or Cisco Secure Email Gateway. If they do, ask when they last applied security patches and whether CVE-2026-76460 and CVE-2026-76461 have been addressed. Get the answer in writing.
-
Check your Microsoft 365 admin portal. Review the service health dashboard for any advisories related to the Azure vulnerabilities disclosed overnight. Microsoft’s response timeline on CVSS 10.0 cloud vulnerabilities is usually rapid, but verify rather than assume.
-
Review your supplier list for cloud dependencies. Which of your critical suppliers use Azure-hosted services? This is not a reason to terminate those relationships. It is a reason to understand your dependency map. If a supplier’s environment is compromised via an Azure vulnerability, how does that affect your data?
-
Document what you did. A short email to your MSP asking about patch status, and their reply, is a record. That record matters for ICO accountability purposes and for any future cyber insurance claim. Do not skip this step.
-
Check your email security configuration. If Cisco Secure Email Gateway is in your supply chain, ask your provider for confirmation that CVE-2026-76461 has been patched. If your email security is delivered through a different platform, verify that platform’s advisory status independently.
The briefing on these vulnerabilities will be on the podcast feed today. Before you go: follow the show wherever you listen, leave a rating or review, drop a comment with your thoughts, and share this episode with someone who would find it useful. If one business owner asks their MSP the right question this week as a result, this was worth putting out.