New Vulnerabilities Impacting Cisco ISE and Cisco ISE-PIC

The Canadian Centre for Cyber Security (CCCS) has released an advisory detailing vulnerabilities for versions of Cisco ISE and Cisco ISE-PIC.

These vulnerabilities cover three main areas of concern:

Your organization is vulnerable if you are running affected code.

This table summarizes affected and fixed code version for each product:

Affected Product Affected Versions Fixed Versions
Cisco Identity Services Engine (ISE) or ISE-PIC releases prior to 3.0 Migrate to a fixed release
Cisco Identity Services Engine (ISE) or ISE-PIC release 3.1 3.1 Patch 12
Cisco Identity Services Engine (ISE) or ISE-PIC release 3.2 3.2 Patch 11
Cisco Identity Services Engine (ISE) or ISE-PIC release 3.3 3.3 Patch 12
Cisco Identity Services Engine (ISE) or ISE-PIC release 3.4 3.4 Patch 7
Cisco Identity Services Engine (ISE) or ISE-PIC release 3.5 3.5 Patch 4

For more information on these vulnerabilities and fixed code versions, please see Cisco’s security advisory.

It is recommended to patch systems immediately as there are fixes for all three vulnerabilities. CVE-2026-76460 should be prioritized as it is confirmed to be being used in-the-wild. Make sure to review your access logs, isolate web-facing applications, and restrict management interfaces where feasible. Harden your operating systems and applications and install patches regularly.

General guidance for protecting your environment is available from the Canadian Centre for Cyber Security.


SecurityLARG*netCVE, Cisco, ISE