logo

Root Access via Admin: The 9.9 RCE Crisis Threatening Cisco ISE Networks

ID: 6f38b5b0-a545-501a-81b7-83edeb47d69a

STIX ID: report--6f38b5b0-a545-501a-81b7-83edeb47d69a

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-23

Author: Ddos

...
...

Cisco issued an urgent advisory for critical vulnerabilities in Identity Services Engine (ISE) and ISE-PIC: CVE-2026-20147 is a Remote Code Execution bug (CVSS 9.9) and CVE-2026-20148 is a path traversal issue; both require administrative credentials, can lead to OS-level access or sensitive-file disclosure, and may cause DoS on single-node deployments. Cisco reports no workarounds and provides fixed patches across multiple releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.