Missing Authentication for Critical Function in Cisco Identity Services Engine (ISE) - CVE-2026-76447
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause the OCSP responder to reload certificate and key material.
The vulnerability exists due to missing authentication in a function of the Online Certificate Status Protocol (OCSP) responder when handling crafted requests. A remote attacker can send a crafted request to cause the OCSP responder to reload certificate and key material on demand.