Critical Cisco ISE Vulnerabilities Let Remote Attackers Execute Malicious Code
ID: e515758a-09ec-528a-81e6-dfb00c69c365
STIX ID: report--e515758a-09ec-528a-81e6-dfb00c69c365
Feed Name: Cyber Press
Threat Score
Cisco issued an urgent advisory for two vulnerabilities in Identity Services Engine (ISE) and ISE Passive Identity Connector: CVE-2026-20147 (critical RCE, CVSS 9.9) allowing authenticated attackers to execute arbitrary OS commands and potentially escalate to root, and CVE-2026-20148 (path traversal, CVSS 4.9) enabling sensitive file access; Cisco provides specific patch levels for affected versions and reports no known active exploitation or mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
