RaqibCTI
CVE

CVE-2026-76460

P2
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Cisco · Identity Services Engine
Date added (CISA)
2026-09-16
Remediation due
2026-09-19
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date
Associated with
Related to
  • SparrowDoorcampaignCorrelated cluster2026-09-21

Description

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Source: NVD ↗ · CISA KEV Catalog ↗