Cisco disclosed four independent medium-severity vulnerabilities in Cisco Identity Services Engine (ISE); three also affect Cisco ISE Passive Identity Connector (ISE-PIC). Unauthenticated remote attackers could manipulate endpoint posture status, obtain sensitive configuration information, or trigger reloading of OCSP responder certificate and key material. A separate authenticated XML external entity (XXE) vulnerability could allow reading of certain operating-system files.
Cisco released software updates for all affected releases and stated that no workarounds are available. The flaws are independent, and exposure varies by vulnerability and software version; organizations using ISE or ISE-PIC should identify affected deployments and apply Cisco’s updates promptly.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Cisco released software updates addressing CVE-2026-76439, CVE-2026-76444, CVE-2026-76447, and CVE-2026-76446. Cisco stated that no workarounds are available for any of the four flaws.
Cisco disclosed four independent medium-severity vulnerabilities: unauthenticated posture-status manipulation (CVE-2026-76439), configuration disclosure (CVE-2026-76444), OCSP certificate/key-material reload (CVE-2026-76447), and an authenticated XXE file-read flaw (CVE-2026-76446). Three of the flaws also affect Cisco ISE Passive Identity Connector (ISE-PIC).
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
tools.cisco.com
Open sourcebst.cloudapps.cisco.com
Open sourcebst.cloudapps.cisco.com
Open sourcebst.cloudapps.cisco.com
Open sourcebst.cloudapps.cisco.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.