CVE-2026-76447: Cisco Identity Services Engine

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key material. This vulnerability is due to missing authentication on a function of the OCSP responder. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause the OCSP responder to reload certificate and key material on demand.

Affected products

  • Cisco Identity Services Engine: before 3.3.0 (fixed in 3.3.0); version 3.3.0 only; version 3.4.0 only; version 3.5.0 only
  • Cisco Identity Services Engine Passive Identity Connector: before 3.3.0 (fixed in 3.3.0); version 3.3.0 only; version 3.4.0 only

Published 2026-09-16. Last modified 2026-09-28.