Cisco Identity Services Engine Software

44 known vulnerabilities in Cisco Identity Services Engine Software, 15 critical, 3 actively exploited, with patch priority, exploit likelihood and the news…

Recently exploited

  • CVE-2026-76460 CVSS 10.0 critical · actively exploited Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
  • CVE-2025-20337 CVSS 10.0 critical · actively exploited Cisco Identity Services Engine Injection Vulnerability
  • CVE-2025-20281 CVSS 10.0 critical · actively exploited Cisco Identity Services Engine Injection Vulnerability

Latest vulnerabilities

  • CVE-2026-76460 CVSS 10.0 critical · actively exploited Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
  • CVE-2026-76451 CVSS 4.9 medium A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated…
  • CVE-2026-76450 CVSS 4.9 medium A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated…
  • CVE-2026-76449 CVSS 4.9 medium A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated…
  • CVE-2026-76448 CVSS 4.9 medium A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated…
  • CVE-2026-76447 CVSS 5.3 medium A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated…
  • CVE-2026-76446 CVSS 4.9 medium A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific files on the…
  • CVE-2026-76444 CVSS 5.3 medium A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve…
  • CVE-2026-76439 CVSS 5.3 medium A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an…
  • CVE-2026-76434 CVSS 4.9 medium A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow…
  • CVE-2026-76433 CVSS 5.3 medium A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker…
  • CVE-2026-76432 CVSS 4.9 medium A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with…
  • CVE-2026-76431 CVSS 4.9 medium A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an…
  • CVE-2026-76428 CVSS 4.9 medium A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection…
  • CVE-2026-76427 CVSS 4.9 medium A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files…
  • CVE-2026-76426 CVSS 4.9 medium A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection…
  • CVE-2026-76425 CVSS 7.6 high A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the…
  • CVE-2026-76424 CVSS 7.2 high A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an…
  • CVE-2026-20352 CVSS 8.6 high A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a…
  • CVE-2026-20309 CVSS 6.1 medium A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote…
  • CVE-2026-20300 CVSS 7.1 high A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected device. To…
  • CVE-2026-20287 CVSS 6.5 medium As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE…
  • CVE-2026-20286 CVSS 4.3 medium A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote…
  • CVE-2026-20285 CVSS 4.3 medium A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector…
  • CVE-2026-20284 CVSS 9.1 critical A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This…
  • CVE-2026-20283 CVSS 6.5 medium A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on…
  • CVE-2026-20282 CVSS 4.9 medium A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an…
  • CVE-2026-20247 CVSS 7.5 high A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This…
  • CVE-2026-20235 CVSS 4.9 medium A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive…
  • CVE-2026-20072 CVSS 4.9 medium A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive…