Cisco ISE Vulnerability Enables Access to Sensitive Data
ID: b023189e-9e24-527b-bea2-a39dbd876baa
STIX ID: report--b023189e-9e24-527b-bea2-a39dbd876baa
Feed Name: GBHackers
Threat Score
**Cisco ISE XXE (CVE-2026-20029):** Cisco disclosed a medium-severity XML External Entity vulnerability in ISE and ISE-PIC that allows authenticated administrative users to read arbitrary files on the host via a malicious XML upload; proof-of-concept code is publicly available, no workarounds exist, and Cisco recommends immediate upgrade to fixed releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
