Patch Cisco ISE bug now before attackers abuse proof-of-concept exploit
ID: 12f4365a-9ddc-5025-9166-4a2b2311a3e9
STIX ID: report--12f4365a-9ddc-5025-9166-4a2b2311a3e9
Feed Name: The Register (Security)
Cisco patched CVE-2026-20029, a medium-severity (CVSS 4.9) vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) caused by improper XML parsing in the web management interface; authenticated attackers with admin-level credentials could upload a malicious file to read arbitrary files on the underlying system. A public proof-of-concept exists, increasing the risk of exploitation, but vendors state they are not aware of active in-the-wild abuse and urge customers to apply the patch promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
