CVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Summary
Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) have a vulnerability that allows unauthenticated, remote attackers to bypass the web-based management interface and gain unauthorized access. Cisco and CISA are advising users to apply mitigations according to vendor instructions and CISA's guidance on prioritizing security updates.
IFF Assessment
This vulnerability allows an unauthenticated, remote attacker to gain unauthorized access to the affected device, posing a significant risk to defenders.
Severity
The vulnerability allows for unauthorized remote access by bypassing authentication and the web-based management interface, indicating a high attack vector and significant impact on confidentiality, integrity, and availability.
CISA KEV: Listed as actively exploited. Federal patch due: September 19, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should be aware of this critical vulnerability affecting Cisco ISE and ISE-PIC. Prompt application of vendor-provided mitigations and adherence to CISA's directives for prioritizing security updates are crucial to prevent unauthorized access and potential compromise.