logo

Critical Cisco ISE Vulnerability Allows Attacker to Execute Malicious Code Remotely

ID: 8352ed9c-46b3-50b0-a609-1adfe17f0254

STIX ID: report--8352ed9c-46b3-50b0-a609-1adfe17f0254

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Abinaya

...
...

Cisco disclosed two critical vulnerabilities in Identity Services Engine (ISE): CVE-2026-20181 (RCE) and CVE-2026-20190 (information disclosure). The flaws affect all ISE and ISE Passive Identity Connector deployments, have a CVSS of 9.1, and can lead to full system compromise or leakage of sensitive credentials; fixes are available for supported releases (ISE 3.3 Patch 11 and 3.4 Patch 6, with 3.5 Patch 4 planned) and organizations are urged to patch immediately and restrict/monitor administrative access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.