CVE-2026-76460: Cisco Identity Services Engine
Cisco身份服務引擎(ISE)和Cisco ISE被動身份聯結器(ISE-PIC)含有對特權API脆弱性的不正確使用,可以讓一個未經認證的遠端攻擊者透過繞過網路管理介面獲得對受影響裝置的未經授權的訪問。
CISA (English)
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
- 廠商
- Cisco
- 產品
- Identity Services Engine
- 漏洞
- Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
- 加入日期
- 2026年9月16日
- CISA 修補期限(美國聯邦機關)
- 2026年9月19日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-648
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02