SEPTEMBER 28, 2026
Live Feed
Back to database
Case File

CVE-2026-76447

MEDIUM · CVSS 5.3 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-09-28

CyberRota Analysis

AI-Generated

The vulnerability affects the Online Certificate Status Protocol (OCSP) responder in Cisco Identity Services Engine (ISE) and Cisco ISE-PIC, allowing unauthenticated remote attackers to send crafted requests that trigger an administrative reload of the OCSP responder's certificate and key material. This could disrupt the certificate validation process, potentially leading to service outages or unauthorized access. Organizations using these Cisco products should prioritize addressing this vulnerability to maintain the integrity of their certificate management systems.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76447
Severity
MEDIUM
CVSS
5.3
EPSS
N/A
Cisco

Original NVD Description

A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key material. This vulnerability is due to missing authentication on a function of the OCSP responder. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause the OCSP responder to reload certificate and key material on demand.

Related CVEs

Other vulnerabilities affecting the same vendor(s)