Résumé
Le 16 septembre 2026, une faille de sécurité a été identifiée dans Cisco Identity Services Engine (ISE).Référencée sous CVE-2026-76460, cette vulnérabilité permet à un attaquant distant non authentifié de contourner la vérification d’identité sur une interface API. En envoyant une requête spécialement fabriquée, il peut obtenir un accès non autorisé à l’équipement en contournant l’interface de gestion web. Cette CVE est référencée dans le catalogue KEV des vulnérabilités activement exploitées. Un code d'exploitation public est disponible.
Solutions
Il est recommandé d'appliquer les correctifs indiqués par le fournisseur.
Dernière mise à jour : 18/09/2026
La faille est activement exploitée : Oui
Details techniques
Score CVSS : 10.0/10
EPSS : 0.92%
Référencée comme KEV : Oui
Code d exploitation disponible : Oui
Systèmes affectés
Cisco Identity Services Engine Software : 3.1.0 p8
Cisco Identity Services Engine Software : 3.1.0 p9
Cisco Identity Services Engine Software : 3.3 Patch 2
Cisco Identity Services Engine Software : 3.3 Patch 1
Cisco Identity Services Engine Software : 3.3 Patch 3
Cisco Identity Services Engine Software : 3.4.0
Cisco Identity Services Engine Software : 3.2.0 p7
Cisco Identity Services Engine Software : 3.3 Patch 4
Cisco Identity Services Engine Software : 3.4 Patch 1
Cisco Identity Services Engine Software : 3.1.0 p10
Cisco Identity Services Engine Software : 3.3 Patch 5
Cisco Identity Services Engine Software : 3.3 Patch 6
Cisco Identity Services Engine Software : 3.4 Patch 2
Cisco Identity Services Engine Software : 3.3 Patch 7
Cisco Identity Services Engine Software : 3.4 Patch 3
Cisco Identity Services Engine Software : 3.5.0
Cisco Identity Services Engine Software : 3.4 Patch 4
Cisco Identity Services Engine Software : 3.3 Patch 8
Cisco Identity Services Engine Software : 3.2 Patch 8
Cisco Identity Services Engine Software : 3.5 Patch 1
Cisco Identity Services Engine Software : 3.3 Patch 9
Cisco Identity Services Engine Software : 3.2 Patch 9
Cisco Identity Services Engine Software : 3.4 Patch 5
Cisco Identity Services Engine Software : 3.5 Patch 3
Cisco Identity Services Engine Software : 3.5 Patch 2
Cisco Identity Services Engine Software : 3.3 Patch 10
Cisco Identity Services Engine Software : 3.3 Patch 11
Cisco Identity Services Engine Software : 3.4 Patch 6
Cisco Identity Services Engine Software : 3.2 Patch 10
Cisco Identity Services Engine Software : 3.1.0 p11
Cisco ISE Passive Identity Connector : 3.4.0
Cisco ISE Passive Identity Connector : 3.5.0
Documentation
NIST NVD : https://nvd.nist.gov/vuln/detail/CVE-2026-76460
CVE Details : https://www.cvedetails.com/cve/CVE-2026-76460/
Référence CVE : https://www.cve.org/CVERecord?id=CVE-2026-76460