SPOJENO AI KEV ✓ EPSS 0.01
Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
Cisco CA SE HU IT NL US FR
CVE v události 4
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-20130 | 10.0 3.1 · cisco | – | 0.00 |
| CVE-2026-20192 | 10.0 3.1 · cisco | – | 0.00 |
| CVE-2026-76423 | 10.0 3.1 · cisco | – | 0.01 |
| CVE-2026-76460 | 10.0 3.1 · cisco | KEV ✓ | 0.01 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.
Dalších 5 CVE zmiňuje jen text zpravodajského článku (CVE-2025-20337, CVE-2026-20176, CVE-2026-20211, CVE-2026-20284, CVE-2026-20307). Nejsou to identifikátory téhle události, proto nejsou v tabulce ani v odznacích.
Jak se o tom psalo 10
-
· Cyber Centre Kanada CA
AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460
Number: AL26-021Date: September 17, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian…
-
· Cyber Centre Kanada CA
Cisco security advisory (AV26-932)
Serial number: AV26-932Date: September 17, 2026 As of September 16, 2026, Cisco is affected by vulnerabilities in the following products: Cisco Secure Firewall Threat Defense (FTD) Software Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0 Cisco Secure Firewall Management Center (FMC) Software Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0 Cisco Identity Services Engine (ISE) Software Prior to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4…
-
· CERT-SE SE
Cisco publicerar säkerhetsuppdateringar för flera sårbarheter
Den 16 september publicerade Cisco säkerhetsuppdateringar för flera sårbarheter, där några av dessa utnyttjas aktivt enligt Cisco. [1, 2] Ett exempel är CVE-2026-76460, en sårbarhet i ett API för Cisco Identity Services Engine (ISE). Framgångsrikt utnyttjande innebär att en oautentiserad angripare kan förbigå autentisering. Sårbarheten har fått en CVSS-klassning på 10.0. [3]
-
· NKI Maďarsko HU
Riasztás Cisco szoftvereket érintő sérülékenységekről
A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Cisco Identity Services Engine (ISE) és az ISE Passive Identity Connector (ISE-PIC) termékeket érintő, CVE-2026-76460 azonosítón nyomon követett kritikus sérülékenység kapcsán. A sebezhetőség kihasználásával a támadók hitelesítés nélkül jogosulatlan hozzáférést szerezhetnek az érintett rendszerhez. A Cisco tájékoztatása szerint a sérülékenység oka, hogy az egyik API-végpont […]
-
· CSIRT Itálie (ACN) IT
Risolte vulnerabilità in prodotti Cisco
Cisco ha rilasciato aggiornamenti di sicurezza che risolvono molteplici nuove vulnerabilità, di cui 24 con gravità “critica” e 25 con gravità “alta”, riguardanti diversi prodotti Cisco. Tra le vulnerabilità rilevate si evidenzia la CVE-2026-76460 che risulta attivamente sfruttata in rete.
-
· NCSC-NL NL
NCSC-2026-0382 [1.00] [H/H] Kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE)
Cisco heeft 21 kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE) en Cisco ISE Passive Identity Connector (ISE-PIC). De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Cisco ISE en ISE-PIC, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van middel tot kritiek. Van de in totaal 21 kwetsbaarheden zijn 13 als kritiek…
-
· BleepingComputer US nadpis události
Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
-
· CERT-FR – avis FR
Multiples vulnérabilités dans les produits Cisco (17 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits Cisco. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. Cisco indique que la vulnérabilité CVE-2026-76460 est...
-
· Cisco PSIRT US
Cisco Identity Services Engine Authentication Bypass Vulnerability
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Cisco has released…
-
· CISA KEV US
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability (CVE-2026-76460)
CISA added CVE-2026-76460 to the Known Exploited Vulnerabilities catalog. Affected product: Cisco Identity Services Engine. Remediation due date: 2026-09-19.