logo

Cisco ISE Vulnerability Enables Access to Sensitive Data

ID: b023189e-9e24-527b-bea2-a39dbd876baa

STIX ID: report--b023189e-9e24-527b-bea2-a39dbd876baa

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Cisco ISE XXE (CVE-2026-20029):** Cisco disclosed a medium-severity XML External Entity vulnerability in ISE and ISE-PIC that allows authenticated administrative users to read arbitrary files on the host via a malicious XML upload; proof-of-concept code is publicly available, no workarounds exist, and Cisco recommends immediate upgrade to fixed releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.