🔥 この記事の詳細
2026-09-17 更新
B
今週中

Cisco Identity Services Engine (ISE) および Cisco ISE Passive Identity Connector…

脆弱性🌐 英語ソース
🖥️ 製品Cisco
🔢 CVECVE-2026-20192CVE-2026-76423CVE-2026-76460
📅 2026-09-17📰 cccs
📌 一言でいうと
Cisco Identity Services Engine (ISE) および Cisco ISE Passive Identity Connector (ISE-PIC) において、複数の脆弱性が報告されました。これらの脆弱性を悪用されると、認証されていない攻撃者が認証制御をバイパスし、管理権限の取得や機密データの操作が行われる可能性があります。ベンダーから修正プログラムが提供されており、速やかな適用が推奨されています。
🔍該当判定
  • Cisco Identity Services Engine (ISE) を導入して運用している
  • Cisco ISE Passive Identity Connector (ISE-PIC) を利用している
  • 社内ネットワークの認証管理に Cisco ISE を使用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
Ciscoが提供する最新のセキュリティアップデートを適用し、脆弱性を修正してください。また、管理インターフェースへのアクセス制限などの緩和策を検討してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Cisco ISE および ISE-PIC の脆弱性 (CVE-2026-20192 他) 対応について

お疲れさまです。Cisco製品の脆弱性に関する情報共有です。

■ 概要
Cisco ISE および ISE-PIC において、認証バイパスや権限昇格につながる複数の脆弱性(CVE-2026-20192, CVE-2026-76423, CVE-2026-76460)が公開されました。攻撃者が認証なしで管理権限を取得し、システムを完全に侵害するリスクがあります。

■ 影響範囲
- Cisco Identity Services Engine (ISE)
- Cisco ISE Passive Identity Connector (ISE-PIC)

■ 対応手順
1. 自社で利用している Cisco ISE / ISE-PIC のバージョンを確認してください。
2. Cisco 公式アドバイザリに基づき、修正済みの最新バージョンへアップデートを適用してください。

■ 参考情報
- Cisco 公式セキュリティアドバイザリ
- Canadian Centre for Cyber Security (AL26-021)

対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Vulnerabilities in Cisco ISE and ISE-PIC (CVE-2026-20192 et al.)

Dear IT Administration Team,

We are sharing critical information regarding vulnerabilities identified in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC).

■ Overview
Multiple vulnerabilities (CVE-2026-20192, CVE-2026-76423, CVE-2026-76460) have been disclosed that could allow unauthenticated attackers to bypass authentication controls and gain administrative access to affected systems.

■ Affected Products
- Cisco Identity Services Engine (ISE)
- Cisco ISE Passive Identity Connector (ISE-PIC)

■ Mitigation Steps
1. Verify the current version of Cisco ISE / ISE-PIC deployed in the environment.
2. Apply the latest security updates provided by Cisco to remediate these vulnerabilities.

■ Reference
- Cisco Official Security Advisory
- Canadian Centre for Cyber Security (AL26-021)

Priority: High
Deadline: Immediate