Executive brief
Cisco Identity Services Engine (ISE) is a network access control platform used to manage device identities and enforce security policies across corporate networks. A vulnerability in its OCSP (certificate status checking) responder allows unauthenticated attackers to force a reload of security certificates and keys on demand, potentially disrupting certificate validation and authentication services.
Technical details
CVE-2026-76447 is a missing authentication vulnerability (CWE-306) in the OCSP responder component of Cisco ISE and ISE-PIC. An unauthenticated remote attacker can send a crafted request to the affected OCSP responder endpoint to trigger an administrative reload of certificate and key material. The attack requires network access to the OCSP responder but no authentication credentials or user interaction. Successful exploitation causes service disruption by forcing certificate reloads, potentially impacting certificate validation operations. Cisco has released software updates to address this vulnerability; no workarounds are available.
Affected products
- Cisco Identity Services Engine Multiple versions; see Cisco advisory for fixed versions
- Cisco ISE Passive Identity Connector Multiple versions; see Cisco advisory for fixed versions
Timeline
- 2026-09-16: disclosed: Cisco Security Advisory published