CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities (KEV) catalogue on 16 September 2026. The vulnerability affects Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Cisco names it the Identity Services Engine Incorrect Use of Privileged APIs Vulnerability.
The flaw involves the incorrect use of privileged application programming interfaces (APIs). An unauthenticated, remote attacker could exploit it to bypass the web-based management interface and gain unauthorised access to an affected device. The available data does not provide a CVSS score or severity rating. Patch availability is currently unknown.
KEV inclusion confirms that attackers are actively exploiting this vulnerability. The available information does not confirm use in ransomware campaigns. CISA set 19 September 2026 as the remediation deadline for affected federal civilian executive branch (FCEB) agencies.
CISA requires organisations to apply mitigations in accordance with Cisco’s instructions, comply with BOD 26-04 guidance on prioritising security updates based on risk, and follow CISA’s Forensics Triage Requirements. Agencies should apply the relevant BOD 26-04 guidance for cloud services or discontinue using the product if mitigations are unavailable. Stakeholders must assess each asset’s internet exposure and follow BOD 26-04 patching requirements. FCEB agencies are directly subject to this requirement, but all organisations should review their exposure.
See the NVD entry and CISA KEV catalogue for full details.