← nejvýznamnější zprávy

SPOJENO AI KEV ✓ EPSS 0.01

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]

10 zpráv z 9 zdrojů · první 16. 9. 02:00 · poslední 17. 9. 19:32 CZ · EN/orig

Cisco CA SE HU IT NL US FR

tg: zneužíváno tg: zranitelnost tp: identita

CVE v události 4

CVEhodnoceníKEVEPSS
CVE-2026-20130 10.0 3.1 · cisco 0.00
CVE-2026-20192 10.0 3.1 · cisco 0.00
CVE-2026-76423 10.0 3.1 · cisco 0.01
CVE-2026-76460 10.0 3.1 · cisco KEV ✓ 0.01

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.

Dalších 5 CVE zmiňuje jen text zpravodajského článku (CVE-2025-20337, CVE-2026-20176, CVE-2026-20211, CVE-2026-20284, CVE-2026-20307). Nejsou to identifikátory téhle události, proto nejsou v tabulce ani v odznacích.

Jak se o tom psalo 10

  1. · Cyber Centre Kanada CA

    AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460

    Number: AL26-021Date: September 17, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian…

  2. · Cyber Centre Kanada CA

    Cisco security advisory (AV26-932)

    Serial number: AV26-932Date: September 17, 2026 As of September 16, 2026, Cisco is affected by vulnerabilities in the following products: Cisco Secure Firewall Threat Defense (FTD) Software Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0 Cisco Secure Firewall Management Center (FMC) Software Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0 Cisco Identity Services Engine (ISE) Software Prior to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4…

  3. · CERT-SE SE

    Cisco publicerar säkerhetsuppdateringar för flera sårbarheter

    Den 16 september publicerade Cisco säkerhetsuppdateringar för flera sårbarheter, där några av dessa utnyttjas aktivt enligt Cisco. [1, 2] Ett exempel är CVE-2026-76460, en sårbarhet i ett API för Cisco Identity Services Engine (ISE). Framgångsrikt utnyttjande innebär att en oautentiserad angripare kan förbigå autentisering. Sårbarheten har fått en CVSS-klassning på 10.0. [3]

  4. · NKI Maďarsko HU

    Riasztás Cisco szoftvereket érintő sérülékenységekről

    A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Cisco Identity Services Engine (ISE) és az ISE Passive Identity Connector (ISE-PIC) termékeket érintő, CVE-2026-76460 azonosítón nyomon követett kritikus sérülékenység kapcsán. A sebezhetőség kihasználásával a támadók hitelesítés nélkül jogosulatlan hozzáférést szerezhetnek az érintett rendszerhez. A Cisco tájékoztatása szerint a sérülékenység oka, hogy az egyik API-végpont […]

  5. · CSIRT Itálie (ACN) IT

    Risolte vulnerabilità in prodotti Cisco

    Cisco ha rilasciato aggiornamenti di sicurezza che risolvono molteplici nuove vulnerabilità, di cui 24 con gravità “critica” e 25 con gravità “alta”, riguardanti diversi prodotti Cisco. Tra le vulnerabilità rilevate si evidenzia la CVE-2026-76460 che risulta attivamente sfruttata in rete.

  6. · NCSC-NL NL

    NCSC-2026-0382 [1.00] [H/H] Kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE)

    Cisco heeft 21 kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE) en Cisco ISE Passive Identity Connector (ISE-PIC). De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Cisco ISE en ISE-PIC, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van middel tot kritiek. Van de in totaal 21 kwetsbaarheden zijn 13 als kritiek…

  7. · BleepingComputer US nadpis události

    Cisco warns of max severity ISE zero-day exploited in attacks

    Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]

  8. · CERT-FR – avis FR

    Multiples vulnérabilités dans les produits Cisco (17 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans les produits Cisco. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. Cisco indique que la vulnérabilité CVE-2026-76460 est...

  9. · Cisco PSIRT US

    Cisco Identity Services Engine Authentication Bypass Vulnerability

    A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Cisco has released…

  10. · CISA KEV US

    Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability (CVE-2026-76460)

    CISA added CVE-2026-76460 to the Known Exploited Vulnerabilities catalog. Affected product: Cisco Identity Services Engine. Remediation due date: 2026-09-19.