Get real-time updates on Telegram
CVE-2026-76460: identity services engine 3.1.0, 3.2.0, 3.3.0 (+2 more affected versions); +3 more affected products
CVE-2026-76460 affects Cisco Identity Services Engine. EPSS 0.14026 (percentile 0.96456), scored 2026-10-03. Listed in CISA KEV, added 2026-09-16.
Affected technology
identity services engine · 3.1.0
cisco
identity services engine · 3.1.0 · update patch1
cisco
identity services engine · 3.1.0 · update patch10
cisco
identity services engine · 3.1.0 · update patch11
cisco
identity services engine · 3.1.0 · update patch2
cisco
identity services engine · 3.1.0 · update patch3
cisco
identity services engine · 3.1.0 · update patch4
cisco
identity services engine · 3.1.0 · update patch5
cisco
identity services engine · 3.1.0 · update patch6
cisco
identity services engine · 3.1.0 · update patch7
cisco
identity services engine · 3.1.0 · update patch8
cisco
identity services engine · 3.1.0 · update patch9
cisco
identity services engine · 3.2.0
cisco
identity services engine · 3.2.0 · update patch1
cisco
identity services engine · 3.2.0 · update patch10
cisco
identity services engine · 3.2.0 · update patch2
cisco
identity services engine · 3.2.0 · update patch3
cisco
identity services engine · 3.2.0 · update patch4
cisco
identity services engine · 3.2.0 · update patch5
cisco
identity services engine · 3.2.0 · update patch6
cisco
identity services engine · 3.2.0 · update patch7
cisco
identity services engine · 3.2.0 · update patch8
cisco
identity services engine · 3.2.0 · update patch9
cisco
identity services engine · 3.3.0
cisco
identity services engine · 3.3.0 · update patch1
cisco
identity services engine · 3.3.0 · update patch10
cisco
identity services engine · 3.3.0 · update patch11
cisco
identity services engine · 3.3.0 · update patch2
cisco
identity services engine · 3.3.0 · update patch3
cisco
identity services engine · 3.3.0 · update patch4
cisco
identity services engine · 3.3.0 · update patch5
cisco
identity services engine · 3.3.0 · update patch6
cisco
identity services engine · 3.3.0 · update patch7
cisco
identity services engine · 3.3.0 · update patch8
cisco
identity services engine · 3.3.0 · update patch9
cisco
identity services engine · 3.4.0
cisco
identity services engine · 3.4.0 · update patch1
cisco
identity services engine · 3.4.0 · update patch2
cisco
identity services engine · 3.4.0 · update patch3
cisco
identity services engine · 3.4.0 · update patch4
cisco
identity services engine · 3.4.0 · update patch5
cisco
identity services engine · 3.4.0 · update patch6
cisco
identity services engine · 3.5.0
cisco
identity services engine · 3.5.0 · update patch1
cisco
identity services engine · 3.5.0 · update patch2
cisco
identity services engine · 3.5.0 · update patch3
cisco
identity services engine passive identity connector · 3.1.0
cisco
identity services engine passive identity connector · 3.1.0 · update patch1
cisco
identity services engine passive identity connector · 3.1.0 · update patch10
cisco
identity services engine passive identity connector · 3.1.0 · update patch11
cisco
identity services engine passive identity connector · 3.1.0 · update patch2
cisco
identity services engine passive identity connector · 3.1.0 · update patch3
cisco
identity services engine passive identity connector · 3.1.0 · update patch4
cisco
identity services engine passive identity connector · 3.1.0 · update patch5
cisco
identity services engine passive identity connector · 3.1.0 · update patch6
cisco
identity services engine passive identity connector · 3.1.0 · update patch7
cisco
identity services engine passive identity connector · 3.1.0 · update patch8
cisco
identity services engine passive identity connector · 3.1.0 · update patch9
cisco
identity services engine passive identity connector · 3.2.0
cisco
identity services engine passive identity connector · 3.2.0 · update patch1
cisco
identity services engine passive identity connector · 3.2.0 · update patch10
cisco
identity services engine passive identity connector · 3.2.0 · update patch2
cisco
identity services engine passive identity connector · 3.2.0 · update patch3
cisco
identity services engine passive identity connector · 3.2.0 · update patch4
cisco
identity services engine passive identity connector · 3.2.0 · update patch5
cisco
identity services engine passive identity connector · 3.2.0 · update patch6
cisco
identity services engine passive identity connector · 3.2.0 · update patch7
cisco
identity services engine passive identity connector · 3.2.0 · update patch8
cisco
identity services engine passive identity connector · 3.2.0 · update patch9
cisco
identity services engine passive identity connector · 3.3.0
cisco
identity services engine passive identity connector · 3.3.0 · update patch1
cisco
identity services engine passive identity connector · 3.3.0 · update patch10
cisco
identity services engine passive identity connector · 3.3.0 · update patch11
cisco
identity services engine passive identity connector · 3.3.0 · update patch2
cisco
identity services engine passive identity connector · 3.3.0 · update patch3
cisco
identity services engine passive identity connector · 3.3.0 · update patch4
cisco
identity services engine passive identity connector · 3.3.0 · update patch5
cisco
identity services engine passive identity connector · 3.3.0 · update patch6
cisco
identity services engine passive identity connector · 3.3.0 · update patch7
cisco
identity services engine passive identity connector · 3.3.0 · update patch8
cisco
identity services engine passive identity connector · 3.3.0 · update patch9
cisco
identity services engine passive identity connector · 3.4.0
cisco
identity services engine passive identity connector · 3.4.0 · update patch1
cisco
identity services engine passive identity connector · 3.4.0 · update patch2
cisco
identity services engine passive identity connector · 3.4.0 · update patch3
cisco
identity services engine passive identity connector · 3.4.0 · update patch4
cisco
identity services engine passive identity connector · 3.4.0 · update patch5
cisco
identity services engine passive identity connector · 3.4.0 · update patch6
cisco
Cisco Identity Services Engine Software · 3.1.0 p8, 3.1.0 p9, 3.3 Patch 2, 3.3 Patch 1, 3.3 Patch 3, 3.4.0, 3.2.0 p7, 3.3 Patch 4, 3.4 Patch 1, 3.1.0 p10, 3.3 Patch 5, 3.3 Patch 6, 3.4 Patch 2, 3.3 Patch 7, 3.4 Patch 3, 3.5.0, 3.4 Patch 4, 3.3 Patch 8, 3.2 Patch 8, 3.5 Patch 1, 3.3 Patch 9, 3.2 Patch 9, 3.4 Patch 5, 3.5 Patch 3, 3.5 Patch 2, 3.3 Patch 10, 3.3 Patch 11, 3.4 Patch 6, 3.2 Patch 10, 3.1.0 p11
Cisco
Cisco ISE Passive Identity Connector · 3.4.0, 3.5.0
Cisco
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
An unauthenticated, remote attacker could bypass authentication. Vendor/CNA’s CVSS 3.1 assessment (base score 10.0/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-648
- Vendor
- Cisco
- Product
- Identity Services Engine
- CCR priority
- 80.0 /100 (P1)
- CVSS 3.1
- 10.0 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H · Vendor/CNA
- EPSS
- 0.14026 · percentile 0.96478 · 2026-10-10
- KEV
- yes · added 2026-09-16 · due 2026-09-19
- Exploit signals
- CISA KEV listing.
Required action — CISA
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Provenance
- CISA Known Exploited Vulnerabilities Catalog (JSON) · Source record · observed 2026-10-04 05:55:03.893835+00:00 UTC
- Cisco Security Advisories RSS · Source record · observed 2026-10-04 07:41:32.000549+00:00 UTC
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-10 21:26:32.650893+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-07 23:02:50.240617+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-76460.html