CYBER CODE RED

Get real-time updates on Telegram

P1Verified

CVE-2026-76460: identity services engine 3.1.0, 3.2.0, 3.3.0 (+2 more affected versions); +3 more affected products

CVE-2026-76460 affects Cisco Identity Services Engine. EPSS 0.14026 (percentile 0.96456), scored 2026-10-03. Listed in CISA KEV, added 2026-09-16.

Affected technology

identity services engine · 3.1.0
cisco

identity services engine · 3.1.0 · update patch1
cisco

identity services engine · 3.1.0 · update patch10
cisco

identity services engine · 3.1.0 · update patch11
cisco

identity services engine · 3.1.0 · update patch2
cisco

identity services engine · 3.1.0 · update patch3
cisco

identity services engine · 3.1.0 · update patch4
cisco

identity services engine · 3.1.0 · update patch5
cisco

identity services engine · 3.1.0 · update patch6
cisco

identity services engine · 3.1.0 · update patch7
cisco

identity services engine · 3.1.0 · update patch8
cisco

identity services engine · 3.1.0 · update patch9
cisco

identity services engine · 3.2.0
cisco

identity services engine · 3.2.0 · update patch1
cisco

identity services engine · 3.2.0 · update patch10
cisco

identity services engine · 3.2.0 · update patch2
cisco

identity services engine · 3.2.0 · update patch3
cisco

identity services engine · 3.2.0 · update patch4
cisco

identity services engine · 3.2.0 · update patch5
cisco

identity services engine · 3.2.0 · update patch6
cisco

identity services engine · 3.2.0 · update patch7
cisco

identity services engine · 3.2.0 · update patch8
cisco

identity services engine · 3.2.0 · update patch9
cisco

identity services engine · 3.3.0
cisco

identity services engine · 3.3.0 · update patch1
cisco

identity services engine · 3.3.0 · update patch10
cisco

identity services engine · 3.3.0 · update patch11
cisco

identity services engine · 3.3.0 · update patch2
cisco

identity services engine · 3.3.0 · update patch3
cisco

identity services engine · 3.3.0 · update patch4
cisco

identity services engine · 3.3.0 · update patch5
cisco

identity services engine · 3.3.0 · update patch6
cisco

identity services engine · 3.3.0 · update patch7
cisco

identity services engine · 3.3.0 · update patch8
cisco

identity services engine · 3.3.0 · update patch9
cisco

identity services engine · 3.4.0
cisco

identity services engine · 3.4.0 · update patch1
cisco

identity services engine · 3.4.0 · update patch2
cisco

identity services engine · 3.4.0 · update patch3
cisco

identity services engine · 3.4.0 · update patch4
cisco

identity services engine · 3.4.0 · update patch5
cisco

identity services engine · 3.4.0 · update patch6
cisco

identity services engine · 3.5.0
cisco

identity services engine · 3.5.0 · update patch1
cisco

identity services engine · 3.5.0 · update patch2
cisco

identity services engine · 3.5.0 · update patch3
cisco

identity services engine passive identity connector · 3.1.0
cisco

identity services engine passive identity connector · 3.1.0 · update patch1
cisco

identity services engine passive identity connector · 3.1.0 · update patch10
cisco

identity services engine passive identity connector · 3.1.0 · update patch11
cisco

identity services engine passive identity connector · 3.1.0 · update patch2
cisco

identity services engine passive identity connector · 3.1.0 · update patch3
cisco

identity services engine passive identity connector · 3.1.0 · update patch4
cisco

identity services engine passive identity connector · 3.1.0 · update patch5
cisco

identity services engine passive identity connector · 3.1.0 · update patch6
cisco

identity services engine passive identity connector · 3.1.0 · update patch7
cisco

identity services engine passive identity connector · 3.1.0 · update patch8
cisco

identity services engine passive identity connector · 3.1.0 · update patch9
cisco

identity services engine passive identity connector · 3.2.0
cisco

identity services engine passive identity connector · 3.2.0 · update patch1
cisco

identity services engine passive identity connector · 3.2.0 · update patch10
cisco

identity services engine passive identity connector · 3.2.0 · update patch2
cisco

identity services engine passive identity connector · 3.2.0 · update patch3
cisco

identity services engine passive identity connector · 3.2.0 · update patch4
cisco

identity services engine passive identity connector · 3.2.0 · update patch5
cisco

identity services engine passive identity connector · 3.2.0 · update patch6
cisco

identity services engine passive identity connector · 3.2.0 · update patch7
cisco

identity services engine passive identity connector · 3.2.0 · update patch8
cisco

identity services engine passive identity connector · 3.2.0 · update patch9
cisco

identity services engine passive identity connector · 3.3.0
cisco

identity services engine passive identity connector · 3.3.0 · update patch1
cisco

identity services engine passive identity connector · 3.3.0 · update patch10
cisco

identity services engine passive identity connector · 3.3.0 · update patch11
cisco

identity services engine passive identity connector · 3.3.0 · update patch2
cisco

identity services engine passive identity connector · 3.3.0 · update patch3
cisco

identity services engine passive identity connector · 3.3.0 · update patch4
cisco

identity services engine passive identity connector · 3.3.0 · update patch5
cisco

identity services engine passive identity connector · 3.3.0 · update patch6
cisco

identity services engine passive identity connector · 3.3.0 · update patch7
cisco

identity services engine passive identity connector · 3.3.0 · update patch8
cisco

identity services engine passive identity connector · 3.3.0 · update patch9
cisco

identity services engine passive identity connector · 3.4.0
cisco

identity services engine passive identity connector · 3.4.0 · update patch1
cisco

identity services engine passive identity connector · 3.4.0 · update patch2
cisco

identity services engine passive identity connector · 3.4.0 · update patch3
cisco

identity services engine passive identity connector · 3.4.0 · update patch4
cisco

identity services engine passive identity connector · 3.4.0 · update patch5
cisco

identity services engine passive identity connector · 3.4.0 · update patch6
cisco

Cisco Identity Services Engine Software · 3.1.0 p8, 3.1.0 p9, 3.3 Patch 2, 3.3 Patch 1, 3.3 Patch 3, 3.4.0, 3.2.0 p7, 3.3 Patch 4, 3.4 Patch 1, 3.1.0 p10, 3.3 Patch 5, 3.3 Patch 6, 3.4 Patch 2, 3.3 Patch 7, 3.4 Patch 3, 3.5.0, 3.4 Patch 4, 3.3 Patch 8, 3.2 Patch 8, 3.5 Patch 1, 3.3 Patch 9, 3.2 Patch 9, 3.4 Patch 5, 3.5 Patch 3, 3.5 Patch 2, 3.3 Patch 10, 3.3 Patch 11, 3.4 Patch 6, 3.2 Patch 10, 3.1.0 p11
Cisco

Cisco ISE Passive Identity Connector · 3.4.0, 3.5.0
Cisco

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

An unauthenticated, remote attacker could bypass authentication. Vendor/CNA’s CVSS 3.1 assessment (base score 10.0/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-648
Vendor
Cisco
Product
Identity Services Engine
CCR priority
80.0 /100 (P1)
CVSS 3.1
10.0 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H · Vendor/CNA
EPSS
0.14026 · percentile 0.96478 · 2026-10-10
KEV
yes · added 2026-09-16 · due 2026-09-19
Exploit signals
CISA KEV listing.

Required action — CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-76460.html