CISA adds Cisco ISE CVE-2026-76460 to exploited vulnerabilities list
On 16 September 2026, CISA added CVE-2026-76460 to its Known Exploited Vulnerabilities catalog. The flaw in Cisco Identity Services Engine stems from incorrect use of privileged APIs, letting a lower-privileged actor trigger operations that should require higher privilege.
- CVE-2026-76460 was added to CISA's KEV catalog on 16 September 2026
- The flaw affects Cisco Identity Services Engine, a network access control platform
- Root cause is incorrect use of privileged APIs
- Ransomware campaign use is listed as unknown
Read next
Security