CVE-2026-76460: Cisco Identity Services Engine
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
- Vendor
- Cisco
- Product
- Identity Services Engine
- Vulnerability
- Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
- Date added
- Sep 16, 2026
- CISA due date (U.S. federal agencies)
- Sep 19, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-648
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.02