AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460
Canada's Cyber Centre alerts on three actively exploited Cisco ISE/ISE-PIC vulnerabilities enabling unauthenticated administrative access and data tampering.
Canada's Cyber Centre issued alert AL26-021 for three flaws in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC): CVE-2026-20192 (improper access control, CWE-284), CVE-2026-76423 (authentication bypass by spoofing, CWE-290), and CVE-2026-76460 (incorrect use of privileged APIs, CWE-648). Successful exploitation could let unauthenticated attackers bypass authentication, gain administrative access, and read or modify ISE configuration and identity data. Cisco confirmed active exploitation of CVE-2026-76460, which CISA added to its KEV catalog on September 16, 2026. Fixes ship in ISE 3.1–3.5 patches, and defenders are urged to prioritize that CVE, restrict management interfaces, and hunt for IoCs.