HIGHVulnerability
Verified
Global
CISA KEV: Cisco Identity Services Engine — Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
·Source: CISA KEV
Updated:
Executive Summary
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Analysis
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-16. Remediation due: 2026-09-19.