AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460

Canadian Centre for Cyber Security Version 1 original current

Imported from official source

Number: AL26-021Date: September 17, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian Centre for Cyber Security (Cyber Centre) is aware of multiple vulnerabilities impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC)Footnote 1. Successful exploitation could allow unauthenticated attackers to bypass authentication controls, gain administrative access, access or modify sensitive data, and potentially compromise affected systems. In response to the vendor advisory released on September 16, 2026, the Cyber Centre released AV26-932 on September 17, 2026Footnote 2. Tracked as CVE-2026-20192Footnote 3, this vulnerability is an Improper Access Control vulnerability (CWE-284)Footnote 4 that may allow an unauthenticated attacker to bypa...

This version

Version
1 of 1
Recorded
September 20, 2026 19:52
Change
Initial
Content hash
1daa70c7e2b23970acbf2b81228ef3b6
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.