CVE-2026-20284: SQL Injection in Cisco ISE SXP REST API
ID: 61210c4d-34b4-57f0-9fe6-bd966463378e
STIX ID: report--61210c4d-34b4-57f0-9fe6-bd966463378e
Feed Name: CosmicBytez Labs
**Executive Summary:** Cisco disclosed CVE-2026-20284, a critical (CVSS 9.1) SQL injection in the SXP REST API of Cisco Identity Services Engine (ISE) that allows an authenticated administrator to manipulate backend database queries when SXP is enabled and at least one SXP connection exists; Cisco published fixes (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4) and recommends restricting API access, disabling unused SXP, enforcing MFA and least privilege for admin accounts, monitoring logs for SQL-like payloads, and rotating secrets if compromise is suspected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
