Executive Summary
CVE-2026-76447 is a missing authentication flaw in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC that lets an unauthenticated, remote attacker send a crafted request and force an administrative reload of the responder certificate and key material. In OT environments where ISE governs network access decisions for engineering workstations, HMIs, and jump hosts, an attacker who can repeatedly trigger this reload can degrade the availability of certificate validation that access control depends on.
Technical Exposure Breakdown
The defect sits in a function of the OCSP responder that does not enforce authentication before acting. OCSP is the mechanism a relying party uses to ask whether a specific certificate has been revoked. A crafted request to the affected device causes the responder to reload its certificate and key material on demand. The published CVSS score is 5.3, consistent with an availability-oriented weakness reachable without credentials rather than a code execution or key disclosure event.
The important characteristic here is the reach. OCSP responders are, by design, exposed so that relying parties across the network can query revocation status. That same exposure means the attack surface is not confined to an administrative management VLAN. Any host that can reach the responder endpoint can send the crafted request. Repeated triggering forces the responder into a churn state where legitimate revocation queries may fail or return late, and any process gated on a valid OCSP response inherits that failure.
Per the grounding data, patch status is unknown and no specific fixed version, advisory revision, or affected version range is confirmed. Treat the exposure as present across deployed ISE and ISE-PIC instances until the vendor advisory confirms fixed builds. This CVE is not currently listed in the known exploited vulnerability catalog.
OT Impact and Compliance Risk
Cisco ISE is frequently the policy enforcement point that decides which devices attach to plant and substation networks. When OCSP validation is part of that decision path, an attacker who keeps the responder in a reload loop can produce inconsistent access outcomes. Depending on the fail mode configured, that means either legitimate devices being denied attachment or, in a fail-open posture, revocation checks being effectively bypassed. Both outcomes are operationally significant. A denied HMI or engineering workstation during a plant event delays operator response. A bypassed revocation check weakens the trust boundary you built ISE to enforce.
The physical criticality is indirect but real. ISE itself does not run the process, but it gates the human and machine access that runs the process. Under IEC 62443, this touches zone and conduit access control and the reliability of your identity and access management components. For NERC CIP registered entities, degradation of the access control system that supports electronic security perimeter enforcement is a documentation and audit concern under CIP-005 and CIP-007. For pipeline operators under TSA SD-02C, the requirement to maintain and monitor access control mechanisms is directly implicated when the authentication decision infrastructure can be disrupted by an unauthenticated remote request. Water utilities operating under AWIA 2018 risk assessment obligations should record this as an availability risk to their access control layer.
Compensating Controls
Do not rely on a future patch as your only response. First, restrict reachability of the OCSP responder to the specific relying parties that legitimately need it. This is a firewall and segmentation exercise: an allow list of known validator hosts to the responder port, with default deny for everything else on the OT side. Do not run active vulnerability scans against ISE responder endpoints in production OT to confirm exposure, since aggressive probing of certificate services and adjacent industrial components can produce unintended state changes.
Second, deploy a virtual patch at the network layer. A Suricata rule concept: alert and, where inline enforcement is available, drop on OCSP request patterns to the responder that originate from source addresses outside the sanctioned validator list, and add a rate anomaly signature that fires when reload-triggering requests arrive above a normal query baseline. This gives you detection of exploitation attempts even before the vendor fix is applied.
Third, review your fail mode. Decide explicitly whether a responder disruption should fail closed or fail open for OT access, and document that decision so an audit does not interpret an availability gap as an undocumented bypass.
BreachSpider Intel
BreachSpider tracks CVE-2026-76447 exploitation signatures and vendor advisory revisions so OT teams get notified the moment a confirmed fix or in-the-wild activity changes the risk picture.