logo

Cisco fixed a critical ISE vulnerability that lets attackers to gain root access

ID: f0e2d9b1-c27e-57ee-b025-2ba81f70d80b

STIX ID: report--f0e2d9b1-c27e-57ee-b025-2ba81f70d80b

Feed Name: Security Affairs

Threat Score
72/100

Date Published: 2026-06-18

Date Updated: 2026-06-19

Author: Pierluigi Paganini

...
...

Cisco addressed a critical ISE vulnerability (CVE-2026-20181, CVSS 9.1) that allows an authenticated administrator to send crafted HTTP requests to execute commands on the underlying OS and escalate to root; in single-node deployments exploitation may also cause a denial-of-service. Cisco released fixes for ISE/ISE-PIC (3.3 Patch 11, 3.4 Patch 6) and a hotfix for 3.5, and also patched CVE-2026-20190, a high-severity information-disclosure issue; PSIRT reports no known in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.