Erforderlich für den Betrieb der Seite (Login, Einstellungen, Sicherheit). Immer aktiv.
Cisco ISE in CISA KEV — Patch-Advisory für MSP-Ops
CVE-2026-76460 ISE Auth-Bypass — aktive Ausnutzung; CISA KEV 16.09.2026. Nur Patches. Kein PoC.
· BAN: exploit steps, payloads, PoC, bypass reproduction, attack procedures.
On , Cisco published an advisory for an authentication-bypass class issue in Cisco ISE / ISE-PIC tracked as CVE-2026-76460, stating awareness of active exploitation. The same day, CISA added the CVE to the Known Exploited Vulnerabilities (KEV) catalog. Public summaries often cite a U.S. federal civilian (FCEB) remediation due around — confirm on CISA KEV for your obligation set.
Remediation = vendor patches only. Cisco states there is no workaround that fully addresses the vulnerability. Fixed trains commonly cited from the advisory:
- 3.1 → Patch 12
- 3.2 → Patch 11
- 3.3 → Patch 12
- 3.4 → Patch 7
- 3.5 → Patch 4
- 3.0 → End of Software Maintenance — migrate to a fixed supported release
Temporary risk reduction discussed by Cisco includes restricting management / control-plane exposure (e.g. infrastructure ACLs) until every node is patched — still not a full fix. Public guidance for MSP/SEC desks: inventory ISE/ISE-PIC nodes, schedule emergency patch windows, review access logs / external telemetry per vendor and CISA notes, and escalate suspected compromise with forensic triage — without publishing or requesting exploit details.
FAQ
Was sollten MSP-Ops zuerst tun?
Alle ISE/ISE-PIC-Knoten inventarisieren; passenden Fixed-Patch einspielen (oder von 3.0 migrieren); Management-Plane einschränken; Logs nach Vendor/CISA triagieren — keine öffentlichen PoCs jagen.
Was öffentlich NICHT tun?
Keine Bypass-/Exploit-Schritte, Payloads oder Angriffsverfahren teilen, anfordern oder reproduzieren. Nur patchen und härten.
Soft: Tenant-Isolation auf der MSP-Control-Plane ≠ ISE patchen — komplementäre Kontrollen.
Sources
- Cisco Security Advisory — ISE authentication bypass (CVE-2026-76460)
- Cisco — ISE hardening advisory (companion)
- CISA — KEV additions 16 Sep 2026
Draft only — patch-advisory framing for MSP ops.