As cited
Copy frozen at (site build).
vulnerabilities
NCSC-2026-0382 [1.00] [H/H] Kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE)
Cisco patched 21 vulnerabilities in Identity Services Engine (ISE) and ISE Passive Identity Connector, with 13 rated critical and CVSS scores ranging from medium to 10.0. Four vulnerabilities (CVE-2026-20130, CVE-2026-20192, CVE-2026-76423, and CVE-2026-76460) carry the highest severity score, enabling unauthenticated remote attackers to gain administrative access, execute arbitrary commands with root privileges, and bypass authentication controls. CVE-2026-76460 is reported as actively exploited.
Why it matters: Organizations running Cisco ISE or ISE-PIC should prioritize patching the four critical remote code execution vulnerabilities, particularly CVE-2026-76460, which is under active attack and allows root-level command execution without authentication.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
NCSC-2026-0382 [1.00] [H/H] Kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE)
Cisco patched 21 vulnerabilities in Identity Services Engine (ISE) and ISE Passive Identity Connector, with 13 rated critical and CVSS scores ranging from medium to 10.0. Four vulnerabilities (CVE-2026-20130, CVE-2026-20192, CVE-2026-76423, and CVE-2026-76460) carry the highest severity score, enabling unauthenticated remote attackers to gain administrative access, execute arbitrary commands with root privileges, and bypass authentication controls. CVE-2026-76460 is reported as actively exploited.
Why it matters: Organizations running Cisco ISE or ISE-PIC should prioritize patching the four critical remote code execution vulnerabilities, particularly CVE-2026-76460, which is under active attack and allows root-level command execution without authentication.
- Source published
- First seen by Cybersecurity Tracker