CVE-2026-76460: Cisco Identity Services Engine
Cisco Identity Services Engine (ISE) 및 Cisco ISE Passive Identity Connector (ISE-PIC)는 웹 기반 관리 인터페이스를 우회하여 영향을받는 장치에 대한 무단 액세스 권한을 얻기 위해 비공식적 인 원격 공격자를 허용 할 수있는 특이한 APIs 취약점의 잘못된 사용을 포함합니다.
CISA (English)
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
- 공급업체
- Cisco
- 제품
- Identity Services Engine
- 취약점
- Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
- 추가일
- 2026. 9. 16.
- CISA 조치 기한(미국 연방기관)
- 2026. 9. 19.
- 랜섬웨어 공격 악용
- 알 수 없음
- 약점(CWE)
- CWE-648
참고 자료
이 사이트는 정보 제공 목적으로 CISA 카탈로그를 요약한 것이며 보안 조언이 아닙니다. 공급업체 안내와 공식 권고를 따르세요.
최종 업데이트: · 카탈로그 버전 2026.10.02