logo

Critical Cisco ISE Vulnerabilities Let Remote Attackers Execute Malicious Code

ID: e515758a-09ec-528a-81e6-dfb00c69c365

STIX ID: report--e515758a-09ec-528a-81e6-dfb00c69c365

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-16

Date Updated: 2026-04-16

Author: AnuPriya

...
...

Cisco issued an urgent advisory for two vulnerabilities in Identity Services Engine (ISE) and ISE Passive Identity Connector: CVE-2026-20147 (critical RCE, CVSS 9.9) allowing authenticated attackers to execute arbitrary OS commands and potentially escalate to root, and CVE-2026-20148 (path traversal, CVSS 4.9) enabling sensitive file access; Cisco provides specific patch levels for affected versions and reports no known active exploitation or mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.