CVE-2026-76447: Cisco Identity Services Engine
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key material. This vulnerability is due to missing authentication on a function of the OCSP responder. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause the OCSP responder to reload certificate and key material on demand.
Affected products
- Cisco Identity Services Engine: before 3.3.0 (fixed in 3.3.0); version 3.3.0 only; version 3.4.0 only; version 3.5.0 only
- Cisco Identity Services Engine Passive Identity Connector: before 3.3.0 (fixed in 3.3.0); version 3.3.0 only; version 3.4.0 only
Published 2026-09-16. Last modified 2026-09-28.