logo

Cisco Discloses '10' Flaw in ISE, ISE-PIC — Patch Now

ID: ff9b208c-4368-5cd8-865f-ae0cb21e6d46

STIX ID: report--ff9b208c-4368-5cd8-865f-ae0cb21e6d46

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-07-17

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Cisco disclosed a critical unauthenticated remote root RCE (CVE-2025-20337, CVSS 10) affecting Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector, related to two other high-severity ISE vulnerabilities; Cisco recommends upgrading to 3.3 Patch 7 or 3.4 Patch 2 because prior hot patches do not address the new flaw. While Cisco reports no known active exploitation, public proof-of-concept exploits and scan traffic have been observed, and the flaws can be exploited without credentials via vulnerable APIs or file upload validation issues, so organizations should assess exposure and apply the provided updates promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.