logo

Public PoC prompts Cisco patch for ISE, ISE-PIC vulnerability

ID: 26c76dfe-5e73-5353-b025-8da3f08dadf1

STIX ID: report--26c76dfe-5e73-5353-b025-8da3f08dadf1

Feed Name: Security Affairs

Threat Score
35/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Cisco patched a medium-severity XML parsing vulnerability (CVE-2026-20029, CVSS 4.9) in ISE and ISE-PIC that allows an authenticated administrator to upload a crafted file and read arbitrary files on the underlying OS; a public proof-of-concept exists, affected versions and fixed releases are listed, and Cisco reports no evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.