CVE-2026-76447: Cisco Identity Services Engine Certificate Reload Vulnerability

Published Sep 16, 2026
·
Updated

A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key material. This vulnerability is due to missing authentication on a function of the OCSP responder. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause the OCSP responder to reload certificate and key material on demand.

Affected Software

2 affected components
Cisco Identity Services Engine (ISE)
Cisco Identity Services Engine - Passive Identity Connector (ISE-PIC)

Event History

Sep 16, 2026
CVE Published
via MITRE·08:24 PM
Data Sourced
via MITRE·08:24 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An unauthenticated remote attacker can exploit it by sending a crafted request to an affected Cisco ISE or Cisco ISE-PIC device. No privileges or user interaction are required.

2

What is the operational impact of a successful exploit?

The attacker can trigger an administrative reload of the OCSP responder's certificate and key material on demand. The provided information identifies an availability impact, but does not indicate confidentiality or integrity impact.

3

Is a default deployment affected?

The available information does not state whether the vulnerable OCSP responder function is enabled or exposed by default. Exposure depends on whether an affected device provides the vulnerable OCSP responder function to a remote attacker.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203