In plain language
What this advisory means
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) have several security problems. These problems could let an attacker access or change data, get sensitive information, or force the system to reload security certificates unexpectedly. Cisco has fixed these issues in software updates. There are no temporary fixes that fully solve these problems, so users should update their software to stay safe.
Technical explanation
How the issue affects the environment
Multiple distinct vulnerabilities affect Cisco ISE and ISE-PIC, including insufficient authentication on internal services and injection weaknesses. These issues allow unauthenticated or authenticated remote attackers to submit forged endpoint posture data (CVE-2026-76439), retrieve sensitive configuration from the Policy Runtime Repository Table service (CVE-2026-76444), trigger administrative reload of Online Certificate Status Protocol responder certificates (CVE-2026-76447), and read files through XML external entity injection (CVE-2026-76446). Exploitation involves sending crafted network requests to exposed services without proper authentication, resulting in data manipulation, information disclosure, or forced reloads of cryptographic materials. Cisco issued software updates that address these vulnerabilities. No effective workarounds exist.
Operational impact
Why teams should care
These vulnerabilities can allow attackers to manipulate endpoint security status, disclose sensitive configuration details, or disrupt certificate usage, leading to potential unauthorized access, compromised system integrity, and operational disruption. This risks exposing confidential information and undermining network security policies, potentially affecting business operations and trust.
Immediate action
Upgrade affected Cisco ISE and Cisco ISE-PIC devices to the fixed software releases indicated by Cisco. Regularly consult Cisco's advisories and support pages for upgrade instructions and ensure new releases are properly installed to mitigate these vulnerabilities. No partial workarounds are available, so upgrade is necessary.
Affected and fixed releases
Temporary risk reduction
Cisco has stated that there are no workarounds available to address these vulnerabilities. Complete remediation requires applying the fixed software updates.
Evidence and validation checklist
- Cisco PSIRT Advisory cisco-sa-ise-multiauth-bypass-sgD2HbL4
- Bug IDs CSCwu73771, CSCwu73786, CSCwu73808, CSCwu73832
- CVE entries CVE-2026-76439, CVE-2026-76444, CVE-2026-76446, CVE-2026-76447
- Official fix release notes and upgrade instructions from Cisco
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
