Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223832 vulns · 37/41 feeds (7d)
← Back to list
4.9
CVE-2026-76427
Cisco · Cisco Identity Services Engine Software

Cisco ISE XML External Entity Injection Vulnerability

Description

A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device. This vulnerability is due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity resolution. An attacker could exploit this vulnerability by uploading a crafted offline feed package through the administrative interface. A successful exploit could allow the attacker to read arbitrary files from the file system and issue requests to internal systems from the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.

Affected Products

VendorProductVersions
CiscoCisco Identity Services Engine Software3.1.0, 3.1.0 p1, 3.1.0 p3, 3.1.0 p2, 3.2.0, 3.1.0 p4, 3.1.0 p5, 3.2.0 p1, 3.1.0 p6, 3.2.0 p2, 3.1.0 p7, 3.3.0, 3.2.0 p3, 3.2.0 p4, 3.1.0 p8, 3.2.0 p5, 3.2.0 p6, 3.1.0 p9, 3.3 Patch 2, 3.3 Patch 1, 3.3 Patch 3, 3.4.0, 3.2.0 p7, 3.3 Patch 4, 3.4 Patch 1, 3.1.0 p10, 3.3 Patch 5, 3.3 Patch 6, 3.4 Patch 2, 3.3 Patch 7, 3.4 Patch 3, 3.5.0, 3.4 Patch 4, 3.3 Patch 8, 3.2 Patch 8, 3.5 Patch 1, 3.3 Patch 9, 3.2 Patch 9, 3.4 Patch 5, 3.5 Patch 3, 3.5 Patch 2, 3.3 Patch 10, 3.3 Patch 11, 3.4 Patch 6, 3.2 Patch 10, 3.1.0 p72, 3.1.0 p11, 3.3 Patch 12, 3.2.0, 3.1.0, 3.3.0, 3.4.0, 3.5.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciscisco ise passive identity connectormitre_affected90%
cisidentity services engine (ise)cert_advisory90%
ciscisco secure firewall management centercert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ

Related News (4 articles)

Tier B
BSI Advisories10d ago
[NEU] [hoch] Cisco ISE und ISE-PIC: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
BSI Advisories10d ago
[NEU] [hoch] Cisco Secure Firewall Management Center: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR11d ago
Multiples vulnérabilités dans les produits Cisco (17 septembre 2026)
→ No new info (linked only)
Tier C
VulDB11d ago
CVE-2026-76427 | Cisco Identity Services Engine Software Offline Profiler Feed Service xml external entity reference
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.14.9 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-611
PublishedSep 16, 2026
Last enriched11d ago
Trending Score11
Source articles4
Independent3
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-76447
Cisco Identity Services Engine Certificate Reload Vulnerability
Trending: 13
MEDIUMCVE-2026-20121
CIsco FTD Bypass Access List
Trending: 13
MEDIUMCVE-2026-76426
Cisco ISE REST API SQL Injection Vulnerability
Trending: 11
MEDIUMCVE-2026-76431
Cisco Identity Services Engine Arbitrary File Deletion Vulnerability
Trending: 10
HIGHCVE-2026-20293
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
Trending: 7

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 16, 2026
Discovered by ZDM
Sep 16, 2026