ZeroHour

CVE-2026-76427

large

Authenticated XXE Arbitrary File Read in Cisco Identity Services Engine (ISE)

CVSS 3.1
4.9 medium
EPSS
Published
()
Modified
AI analysis

Cisco ISE contains an XML external entity (XXE) injection flaw (CWE-611) in its offline profiler feed service, caused by parsing attacker-controlled feed metadata with an XML parser that does not disable external entity resolution. An authenticated remote attacker with valid administrative credentials can exploit it by uploading a crafted offline feed package through the administrative interface. Successful exploitation allows the attacker to read arbitrary files from the device's file system and issue requests to internal systems from the ISE appliance (server-side request forgery), though confidentiality-only impact gives it a medium CVSS 4.9. All organizations running Cisco ISE are potentially affected, but exploitation requires administrative access to the management interface, which is typically restricted to internal management networks. No public proof-of-concept or confirmed exploitation of this specific flaw is known, although Cisco has separately warned that another ISE zero-day (an auth bypass rated CVSS 10.0) is being actively exploited, so ISE deployments are currently under attacker attention.

What to do: Upgrade ISE to the fixed release identified in the Cisco security advisory once published, as no fixed version is listed in the available data. Restrict access to the ISE administrative interface to trusted management networks and review logs for unexpected offline feed package uploads or outbound requests originating from ISE appliances. Given that a separate, actively exploited ISE zero-day (CVSS 10.0 auth bypass) has been announced, treat ISE patching as an urgent priority and verify all ISE nodes in the deployment are updated.

Affected
Cisco Identity Services Engine (ISE) - offline profiler feed service
Estimated exposure
largetens of thousands of enterprise deployments worldwide, with likely only a small fraction (low thousands or fewer) of admin interfaces internet-exposed — Cisco ISE is the dominant enterprise NAC/identity platform with a large installed base across enterprises, universities, and government, but the vulnerable administrative interface is usually deployed on internal management networks,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device. This vulnerability is due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity resolution. An attacker could exploit this vulnerability by uploading a crafted offline feed package through the administrative interface. A successful exploit could allow the attacker to read arbitrary files from the file system and issue requests to internal systems from the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.

Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.