Critical Cisco ISE Vulnerability Allows Attacker to Execute Malicious Code Remotely
ID: 8352ed9c-46b3-50b0-a609-1adfe17f0254
STIX ID: report--8352ed9c-46b3-50b0-a609-1adfe17f0254
Feed Name: cybersecurityNews.com
Cisco disclosed two critical vulnerabilities in Identity Services Engine (ISE): CVE-2026-20181 (RCE) and CVE-2026-20190 (information disclosure). The flaws affect all ISE and ISE Passive Identity Connector deployments, have a CVSS of 9.1, and can lead to full system compromise or leakage of sensitive credentials; fixes are available for supported releases (ISE 3.3 Patch 11 and 3.4 Patch 6, with 3.5 Patch 4 planned) and organizations are urged to patch immediately and restrict/monitor administrative access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
