CVE-2026-76428: Cisco ISE Profiler SQL Injection Vulnerability
Quick Answer
Cisco published a Critical-rated advisory that includes CVE-2026-76428, affecting Cisco Identity Services Engine (ISE) under the live advisory's conditions. Cisco explicitly lists the CVE-specific Security Impact Rating (SIR) as Medium; Common Vulnerability Scoring System (CVSS) base 4.9 (Medium). Confirm the exact platform, release, feature, and exposure; preserve relevant evidence; then follow Cisco's CVE-specific First Fixed guidance. Cisco reported no public announcement or malicious use for this CVE at the last check. That status and absence from CISA KEV are time-bounded and do not prove exploitation has never occurred.
Fix Or Immediate Action
What to do now: Confirm the affected product, release, and configuration. Cisco provides no workaround; reduce exposure where operationally feasible. Upgrade to the CVE-specific First Fixed release in Cisco's advisory table.
Last verified: 2026-09-17 UTC from Cisco's advisory and CSAF record. Recheck both the affected-products and fixed-software sections before a production change.
Context
Scope And Impact In Plain Language
Who should check: Anyone who manages Cisco Identity Services Engine (ISE).
When this applies: This vulnerability affect Cisco ISE and Cisco ISE-PIC, regardless of device configuration.
What could happen: An attacker may be able to send crafted database input that exposes or changes data and, in some products, can lead to broader system control.
Not sure? Find the exact product, platform, and version in the management interface or CLI, then compare them with this CVE's affected-products section in Cisco's live advisory.
Status At A Glance
| Product scope | Cisco Identity Services Engine (ISE) |
|---|---|
| CVE | CVE-2026-76428 |
| TechGeeks response tier | P1 — urgent |
| Publication | New final Cisco advisory |
| First published | 2026-09-16T16:00:00+00:00 |
| Last updated | 2026-09-16T16:00:00+00:00 |
| Cisco advisory SIR | Critical |
| CVE-specific Cisco SIR | Medium |
| CVSS base score / severity | 4.9 — Medium |
| CVSS vector | CVSS v3.1 — CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
| CISA KEV at last check | No — this is separate from Cisco severity and is not proof of no exploitation. |
| Cisco exploitation statement | The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory. |
What Happened
CVE-2026-76428: Cisco ISE Profiler SQL Injection Vulnerability A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the session database. This vulnerability is due to certain parameters being concatenated directly into SQL clauses without parameterization. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements in one of the affected parameters. A successful exploit could allow the attacker to read information from the session database. To exploit this vulnerability, the attacker must have valid administrative credentials. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. Bug ID(s): CSCwu43502 CVE ID: CVE-2026-76428 Security Impact Rating (SIR): Medium CVSS Base Score: 4.9 CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected Scope
This vulnerability affect Cisco ISE and Cisco ISE-PIC, regardless of device configuration.
Match the exact hardware or virtual platform, installed train, patch level, enabled service, role, and management or data-plane exposure. A Cisco product-family name alone does not establish applicability.
Steps
What To Do Now
- Confirm. Inventory Cisco Identity Services Engine (ISE) and record platform, exact release, patch level, enabled feature, role, and exposure.
- Preserve. Save UTC context plus off-device authentication, management, firewall, network, endpoint, and SIEM evidence before logs rotate or a disruptive change removes context.
- Scope. Compare each asset with the live Cisco advisory, including configuration prerequisites and exclusions.
- Reduce exposure. Cisco documents no workaround for this CVE. Use only supported exposure controls while preparing the permanent fix.
- Remediate. Confirm the affected product, release, and configuration. Cisco provides no workaround; reduce exposure where operationally feasible. Upgrade to the CVE-specific First Fixed release in Cisco's advisory table.
- Validate. Confirm the resulting version, service health, logging, expected access, an expected denial, failover or cluster state, and representative dependent workflows.
- Escalate. If evidence or exposure creates concern, open incident response and Cisco TAC recovery work rather than treating patch completion as proof of trust.
Fixed Releases And Mitigation
Permanent Fix
Vendor-directed fix path: Confirm the affected product, release, and configuration. Cisco provides no workaround; reduce exposure where operationally feasible. Upgrade to the CVE-specific First Fixed release in Cisco's advisory table.
Cisco method: Use the live advisory's CVE-specific First Fixed Release table.
No compact per-CVE fixed-release table is reproduced here because Cisco may use different First Fixed values by CVE and software train. Use this CVE's live advisory table or Cisco Software Checker; do not infer a fixed release from a combined hardening baseline or another Cisco notice.
Workaround Or Temporary Mitigation
No vendor workaround is documented for CVE-2026-76428. Use supported exposure controls only as temporary risk reduction while preparing the permanent software fix.
Important boundary: A workaround, ACL, exposure reduction, or service restriction can reduce risk while the update is prepared, but it does not patch the vulnerable code, prove every attack path is closed, or erase an earlier compromise.
Investigation And Recovery
Review management authentication, account and privilege changes, API and web requests, configuration changes, crashes or restarts, resource pressure, and relevant external network telemetry for the vulnerable period. Preserve original evidence and follow Cisco TAC or incident-response guidance for containment, credential rotation, trusted rebuild, or service restoration when findings warrant it.
Notes
Exploitation Evidence
Cisco's exact status at the last check: The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.
This CVE was not present in the TechGeeks CISA KEV snapshot at the last check. Cisco's 'not aware' statement and absence from KEV are time-bounded evidence, not claims that exploitation is impossible or has never happened. Severity and exploitation status remain separate signals.
Validation And Boundaries
This notice is documentation-backed. TechGeeks did not reproduce the exploit or independently test every fixed build. It does not prove that all members of the product family are affected, that the activity is widespread, that a clean indicator search excludes compromise, or that an update restored trust. Cisco's live advisory controls affected and fixed release information.
Related TechGeeks Resources
- TechGeeks Security Notice Center
- All Security Notices
- What to Do When a Device Hits CISA KEV
- Router CVE Exposure, Version, and Mitigation Checklist
- IoT Firmware Update and End-of-Support Checklist
- Live Protect and Runtime Vulnerability Shielding
References
Wrap-Up
Record whether CVE-2026-76428 applies. If it does, assign an owner and deadline appropriate to the Critical Cisco advisory SIR, preserve the evidence, complete Cisco's remediation, and document the validated result.
Correction policy: A material Cisco revision to scope, severity, exploitation status, workarounds, fixed software, or recovery guidance triggers an update and a new verification date.

