CVE-2026-76460CISA KEVEPSS p96.5%

CVE-2026-76460Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Cisco / Identity Services Engine

Description

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Scoring

CVSS 10.0 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS14.03% probability of exploitation · percentile 96.5% · 2026-10-04T12:00:21Z
Last modified2026-09-25

CISA KEV entry

Added to KEV: 2026-09-16

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.