CVE-2026-76460: Cisco Identity Services Engine
Cisco Identity サービス エンジン(ISE)およびCisco ISE パッシブ Identity コネクタ(ISE-PIC)は、Web ベースの管理インターフェイスを迂回することにより、影響を受けるデバイスへの不正なアクセスを得るための、不正なアクセスを可能にする特権 API 脆弱性の誤った使用が含まれています。
CISA (English)
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
- ベンダー
- Cisco
- 製品
- Identity Services Engine
- 脆弱性
- Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
- 追加日
- 2026/09/16
- CISA対応期限(米国連邦機関向け)
- 2026/09/19
- ランサムウェア攻撃での利用
- 不明
- 弱点(CWE)
- CWE-648
参考情報
当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。
最終更新: · カタログのバージョン 2026.10.02