Product

Identity Services Engine

Made by Cisco. 3 of its vulnerabilities are known to have been exploited.

Coverage

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability (CVE-2026-76460) is being actively exploited, CISA warns

CISA added CVE-2026-76460 (Cisco Identity Services Engine) to its Known Exploited Vulnerabilities catalog on September 16, 2026, which means there is reliable evidence of exploitation in the wild. Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized…

Why it matters

CISA lists this as exploited in the wild. Unpatched Cisco networking & security and Identity Services Engine systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Actively exploited

Cisco Identity Services Engine

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Added Sep 16, 2026Fed. due Sep 19, 2026Coverage →

Cisco Identity Services Engine

Cisco Identity Services Engine Injection Vulnerability

Added Jul 28, 2025Fed. due Aug 18, 2025

Cisco Identity Services Engine

Cisco Identity Services Engine Injection Vulnerability

Added Jul 28, 2025Fed. due Aug 18, 2025