Cisco Zero-Day Alert

A second zero-day vulnerability in as many days affects Cisco Identity Services Engine, with a maximum-severity rating and a significant impact on network security.

Bottom line: A second zero-day vulnerability in as many days affects Cisco Identity Services Engine, with a maximum-severity rating and a significant impact on network security.

What's happening: Cisco has issued a security advisory for Cisco Identity Services Engine (ISE), a product hit with three actively exploited vulnerabilities since June 2025. A second zero-day vulnerability, CVE-2025-4493, has been discovered and is being actively exploited by threat actors. The vulnerability has a CVSS score of 9.8 and is rated as Critical.

What to do: Security teams should immediately check for the presence of the vulnerability on their ISE systems and apply the latest patch, which was released on June 2025. Additionally, security leaders should review their incident response plans to ensure they are prepared to respond to a potential breach.

Source: CyberScoop