Executive Summary
CVE-2026-76444 is a missing authentication flaw in the Policy Runtime Repository Table (PRRT) service of Cisco ISE and Cisco ISE-PIC that lets an unauthenticated remote attacker retrieve sensitive configuration information by sending a crafted request. In OT environments where ISE governs who and what connects to control networks, disclosure of that configuration hands an attacker the map of your segmentation and authentication logic before they ever touch a PLC.
Technical Exposure Breakdown
The vulnerable component is an internal service, the PRRT service, that should never have been reachable without authentication. The defect is not memory corruption or code execution. It is an information disclosure primitive rated 5.3 CVSS, which reads as moderate on an IT scorecard and undersells its real value in a targeted intrusion.
The attack vector is a single crafted request to the affected service. No credentials are required. No user interaction is required. The precondition is straightforward network reachability to the PRRT service on the affected device. In a properly designed deployment the ISE management and services planes are isolated, but in practice these appliances frequently sit in shared administrative VLANs that both IT and OT staff can reach.
What an attacker recovers is configuration information from the policy engine. In a network access control platform that configuration is the crown jewel. It can expose authorization policy structure, endpoint identity groups, segmentation assignments, and the shape of the trust model that decides which devices are permitted onto which network segments. This is reconnaissance that normally costs an attacker weeks of internal movement, delivered by an unauthenticated request.
OT Impact and Compliance Risk
Cisco ISE is a common enforcement point for dot1x authentication, MAC authentication bypass, and dynamic VLAN assignment in converged IT and OT networks. When operators use ISE profiling and posture to keep engineering workstations, HMIs, and field devices on the correct segments, the ISE configuration is the authoritative description of that segmentation. Disclosing it tells an attacker exactly where the enforcement boundaries are and, by inference, where the gaps are.
Nothing physical breaks the moment this vulnerability is read. The physical criticality is second order. The exposure erodes the confidentiality of your access control model, which is the foundation that keeps unauthorized devices off Purdue Level 2 and Level 1 networks. An attacker who understands your policy structure can craft an endpoint that satisfies your profiling rules and slides onto a control segment without tripping enforcement.
For compliance this touches IEC 62443 zone and conduit definitions directly, because ISE is often the technical control that implements those conduits. Under NERC CIP the ISE configuration is electronic security perimeter design detail and its unauthorized disclosure is a CIP-005 and CIP-007 concern. For pipeline operators subject to TSA SD-02C, the segmentation and access control measures documented in your cybersecurity implementation plan depend on the integrity and confidentiality of exactly this kind of policy data. Water utilities under AWIA 2018 that rely on network access control for OT isolation face the same erosion of a control they have attested to.
Compensating Controls
Do not respond to this with an active vulnerability scan against production ISE nodes that are inline for OT authentication. Aggressive probing of an appliance that gates dot1x can trigger authentication failures that lock legitimate field devices off the network, and active scanning of adjacent industrial components can brick them outright. Validate exposure from configuration review and passive traffic inspection, not from a sweep.
First, restrict reachability to the PRRT service using upstream access control lists. This service should be accessible only from the ISE distributed deployment members that legitimately require it, and from nothing else. Treat any path from a general user or OT VLAN to that service as a defect to be closed today.
Second, deploy a virtual patch at the segmentation boundary. A Suricata rule concept here is to alert on and drop inbound requests to the PRRT service port that originate from any source outside the defined ISE node group. Anchor the rule to the specific service destination and an allowlist of known node addresses rather than trying to fingerprint the crafted request payload, which is more brittle.
Third, assume the configuration may already be exposed if the service has been reachable. Review whether your segmentation model still holds if an adversary knows it in full, and rotate any secrets that the policy configuration may reference.
Patch status for CVE-2026-76444 was not confirmed in available data at time of writing. Do not wait on a fix to isolate the service.
BreachSpider Intel
Track CVE-2026-76444 and the exposure of your access control infrastructure with continuous OT vulnerability intelligence from BreachSpider.