VYPR

Cisco Ise

by Cisco Systems, Inc.

CVEs (6)

  • CVE-2026-76460CriKEVSep 16, 2026
    risk 0.65cvss 10.0epss

    A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by…

  • CVE-2026-76425HigSep 16, 2026
    risk 0.49cvss 7.6epss

    A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query.…

  • CVE-2026-20300HigSep 16, 2026
    risk 0.46cvss 7.1epss

    A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to improper…

  • CVE-2026-76447MedSep 16, 2026
    risk 0.34cvss 5.3epss

    A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key material. This vulnerability is due to missing…

  • CVE-2026-76433MedSep 16, 2026
    risk 0.34cvss 5.3epss

    A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient validation of directory traversal character…

  • CVE-2026-76432MedSep 16, 2026
    risk 0.32cvss 4.9epss

    A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability exists because the affected software does…