logo

CVE-2026-20284: SQL Injection in Cisco ISE SXP REST API

ID: 61210c4d-34b4-57f0-9fe6-bd966463378e

STIX ID: report--61210c4d-34b4-57f0-9fe6-bd966463378e

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-09-17

Date Updated: 2026-09-18

...
...

**Executive Summary:** Cisco disclosed CVE-2026-20284, a critical (CVSS 9.1) SQL injection in the SXP REST API of Cisco Identity Services Engine (ISE) that allows an authenticated administrator to manipulate backend database queries when SXP is enabled and at least one SXP connection exists; Cisco published fixes (3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4) and recommends restricting API access, disabling unused SXP, enforcing MFA and least privilege for admin accounts, monitoring logs for SQL-like payloads, and rotating secrets if compromise is suspected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.