{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ise-passive-identity-connector-ise-pic/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":10,"id":"CVE-2026-20192"},{"cvss":10,"id":"CVE-2026-76423"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Identity Services Engine (ISE)","ISE Passive Identity Connector (ISE-PIC)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","cisco","identity-management","authentication-bypass"],"_cs_type":"threat","_cs_vendors":["Cisco"],"content_html":"\u003cp\u003eCisco has disclosed three vulnerabilities impacting the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). The affected versions include releases prior to 3.0, as well as versions 3.1, 3.2, 3.3, 3.4, and 3.5. These flaws, identified as CVE-2026-20192 (Improper Access Control), CVE-2026-76423 (Authentication Bypass by Spoofing), and CVE-2026-76460 (Incorrect Use of Privileged APIs), enable unauthenticated attackers to bypass security controls, modify configurations, and obtain administrative privileges.\u003c/p\u003e\n\u003cp\u003eCisco has confirmed active exploitation of CVE-2026-76460, and it has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Given the high-privilege nature of ISE within network environments, these vulnerabilities pose a significant threat to organizational security, potentially allowing attackers to gain full administrative access to identity and access management systems. Organizations are advised to update to the latest patched releases immediately and restrict management interface access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows unauthenticated attackers to gain unauthorized administrative access to the Cisco ISE platform. This results in the ability to modify identity data, change system configurations, and intercept or manipulate sensitive identity information. In scenarios where ISE is used to control network access or authenticate internal users, successful compromise can lead to broad unauthorized access across the enterprise network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Cisco ISE and ISE-PIC instances to the following patched versions immediately: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4.\u003c/li\u003e\n\u003cli\u003ePrioritize remediation of CVE-2026-76460 due to confirmed in-the-wild exploitation.\u003c/li\u003e\n\u003cli\u003eRestrict network access to management interfaces for all Cisco ISE and ISE-PIC nodes using access control lists (ACLs) and network segmentation to trusted administration networks.\u003c/li\u003e\n\u003cli\u003eReview administrative and API access logs for unauthorized or unexpected configuration changes or anomalous login activity.\u003c/li\u003e\n\u003cli\u003eIf compromise is suspected, re-image affected nodes and perform a full restore from known-good backups as attackers may have achieved persistent administrative access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T19:05:59Z","date_published":"2026-09-17T19:05:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cisco-ise-vulnerabilities/","summary":"Multiple vulnerabilities, including one actively exploited in the wild (CVE-2026-76460), allow unauthenticated attackers to bypass authentication and gain administrative control over Cisco ISE and ISE-PIC deployments.","title":"Critical Vulnerabilities in Cisco Identity Services Engine and ISE-PIC","url":"https://feed.craftedsignal.io/briefs/2026-09-cisco-ise-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - ISE Passive Identity Connector (ISE-PIC)","version":"https://jsonfeed.org/version/1.1"}