logo

Cisco warns of Identity Service Engine flaw with exploit code

ID: 57a83b62-12fe-58bf-925f-c9fd8012748f

STIX ID: report--57a83b62-12fe-58bf-925f-c9fd8012748f

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2026-01-08

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cisco patched an XML parsing (XXE) vulnerability in Identity Services Engine (CVE-2026-20029) and ISE-PIC that could allow authenticated administrators to read arbitrary files; proof-of-concept exploit code is publicly available though Cisco found no evidence of active exploitation. The advisory recommends installing the fixed releases (patches listed per version) and notes other recent Cisco advisories, prior exploited ISE zero-days, and activity by a Chinese-linked group (UAT-9686) against other Cisco products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.