Indispensabili per il funzionamento del sito (login, preferenze, sicurezza). Sempre attivi.
Cisco ISE in CISA KEV — advisory di patch per ops MSP
CVE-2026-76460 bypass auth ISE — sfruttamento attivo; KEV CISA 16 set 2026. Solo patch. No PoC.
· BAN: exploit steps, payloads, PoC, bypass reproduction, attack procedures.
On , Cisco published an advisory for an authentication-bypass class issue in Cisco ISE / ISE-PIC tracked as CVE-2026-76460, stating awareness of active exploitation. The same day, CISA added the CVE to the Known Exploited Vulnerabilities (KEV) catalog. Public summaries often cite a U.S. federal civilian (FCEB) remediation due around — confirm on CISA KEV for your obligation set.
Remediation = vendor patches only. Cisco states there is no workaround that fully addresses the vulnerability. Fixed trains commonly cited from the advisory:
- 3.1 → Patch 12
- 3.2 → Patch 11
- 3.3 → Patch 12
- 3.4 → Patch 7
- 3.5 → Patch 4
- 3.0 → End of Software Maintenance — migrate to a fixed supported release
Temporary risk reduction discussed by Cisco includes restricting management / control-plane exposure (e.g. infrastructure ACLs) until every node is patched — still not a full fix. Public guidance for MSP/SEC desks: inventory ISE/ISE-PIC nodes, schedule emergency patch windows, review access logs / external telemetry per vendor and CISA notes, and escalate suspected compromise with forensic triage — without publishing or requesting exploit details.
FAQ
Cosa devono fare prima gli ops MSP?
Inventario di ogni nodo ISE/ISE-PIC; applicare la patch fissa corrispondente (o migrare da 3.0); restringere il management plane; triage log secondo vendor/CISA — non inseguire PoC pubblici.
Cosa NON fare in pubblico?
Non condividere, richiedere o riprodurre passi di bypass/exploit, payload o procedure d’attacco. Solo patch e hardening.
Soft: isolamento tenant sul control plane MSP ≠ patchare ISE — controlli complementari.
Sources
- Cisco Security Advisory — ISE authentication bypass (CVE-2026-76460)
- Cisco — ISE hardening advisory (companion)
- CISA — KEV additions 16 Sep 2026
Draft only — patch-advisory framing for MSP ops.