CVE-2026-76460: Cisco Identity Services Engine
Cisco Identity Services Engine (ISE) i Cisco ISE Passive Identity Connector (ISE- PIC) zawierają nieprawidłowe użycie uprzywilejowanych czułości API, które mogą umożliwić nieuwierzytelnionemu zdalnemu napastnikowi uzyskanie nieautoryzowanego dostępu do danego urządzenia, pomijając interfejs zarządzania bazujący na sieci.
CISA (English)
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
- Producent
- Cisco
- Produkt
- Identity Services Engine
- Podatność
- Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
- Data dodania
- 16 wrz 2026
- Termin CISA (federalne agencje USA)
- 19 wrz 2026
- Znane użycie w kampaniach ransomware
- Nieznane
- Słabość (CWE)
- CWE-648
Odnośniki
Ta strona podsumowuje katalog CISA wyłącznie w celach informacyjnych. Nie jest to porada dotycząca bezpieczeństwa – postępuj zgodnie z zaleceniami producenta i oficjalnymi komunikatami.
Ostatnia aktualizacja: · Wersja katalogu 2026.10.02