← All news
ARTICLE
22 September 2026

Cisco ISE in CISA KEV — patch advisory for MSP ops

CVE-2026-76460 ISE/ISE-PIC auth bypass — active exploitation; CISA KEV 16 Sep 2026. Patch trains only. No PoC.

· BAN: exploit steps, payloads, PoC, bypass reproduction, attack procedures.

On , Cisco published an advisory for an authentication-bypass class issue in Cisco ISE / ISE-PIC tracked as CVE-2026-76460, stating awareness of active exploitation. The same day, CISA added the CVE to the Known Exploited Vulnerabilities (KEV) catalog. Public summaries often cite a U.S. federal civilian (FCEB) remediation due around — confirm on CISA KEV for your obligation set.

Remediation = vendor patches only. Cisco states there is no workaround that fully addresses the vulnerability. Fixed trains commonly cited from the advisory:

  • 3.1 → Patch 12
  • 3.2 → Patch 11
  • 3.3 → Patch 12
  • 3.4 → Patch 7
  • 3.5 → Patch 4
  • 3.0 → End of Software Maintenance — migrate to a fixed supported release

Temporary risk reduction discussed by Cisco includes restricting management / control-plane exposure (e.g. infrastructure ACLs) until every node is patched — still not a full fix. Public guidance for MSP/SEC desks: inventory ISE/ISE-PIC nodes, schedule emergency patch windows, review access logs / external telemetry per vendor and CISA notes, and escalate suspected compromise with forensic triage — without publishing or requesting exploit details.

FAQ

What should MSP ops do first?

Inventory every ISE/ISE-PIC node and train; apply the matching fixed patch (or migrate off 3.0); restrict management-plane exposure until done; triage logs per vendor/CISA — do not chase public PoCs.

What NOT to do publicly?

Do not share, request, or reproduce bypass/exploit steps, payloads, or attack procedures. Patch and harden only.

Soft: tenant isolation on an MSP control plane ≠ patching ISE — complementary controls, different blast-radius problems.

Sources

Draft only — patch-advisory framing for MSP ops.