← Alle News
ARTIKEL
22. September 2026

Cisco ISE in CISA KEV — Patch-Advisory für MSP-Ops

CVE-2026-76460 ISE Auth-Bypass — aktive Ausnutzung; CISA KEV 16.09.2026. Nur Patches. Kein PoC.

· BAN: exploit steps, payloads, PoC, bypass reproduction, attack procedures.

On , Cisco published an advisory for an authentication-bypass class issue in Cisco ISE / ISE-PIC tracked as CVE-2026-76460, stating awareness of active exploitation. The same day, CISA added the CVE to the Known Exploited Vulnerabilities (KEV) catalog. Public summaries often cite a U.S. federal civilian (FCEB) remediation due around — confirm on CISA KEV for your obligation set.

Remediation = vendor patches only. Cisco states there is no workaround that fully addresses the vulnerability. Fixed trains commonly cited from the advisory:

  • 3.1 → Patch 12
  • 3.2 → Patch 11
  • 3.3 → Patch 12
  • 3.4 → Patch 7
  • 3.5 → Patch 4
  • 3.0 → End of Software Maintenance — migrate to a fixed supported release

Temporary risk reduction discussed by Cisco includes restricting management / control-plane exposure (e.g. infrastructure ACLs) until every node is patched — still not a full fix. Public guidance for MSP/SEC desks: inventory ISE/ISE-PIC nodes, schedule emergency patch windows, review access logs / external telemetry per vendor and CISA notes, and escalate suspected compromise with forensic triage — without publishing or requesting exploit details.

FAQ

Was sollten MSP-Ops zuerst tun?

Alle ISE/ISE-PIC-Knoten inventarisieren; passenden Fixed-Patch einspielen (oder von 3.0 migrieren); Management-Plane einschränken; Logs nach Vendor/CISA triagieren — keine öffentlichen PoCs jagen.

Was öffentlich NICHT tun?

Keine Bypass-/Exploit-Schritte, Payloads oder Angriffsverfahren teilen, anfordern oder reproduzieren. Nur patchen und härten.

Soft: Tenant-Isolation auf der MSP-Control-Plane ≠ ISE patchen — komplementäre Kontrollen.

Sources

Draft only — patch-advisory framing for MSP ops.