Cisco warns of Identity Service Engine flaw with exploit code
ID: 57a83b62-12fe-58bf-925f-c9fd8012748f
STIX ID: report--57a83b62-12fe-58bf-925f-c9fd8012748f
Feed Name: Bleeping Computer
Cisco patched an XML parsing (XXE) vulnerability in Identity Services Engine (CVE-2026-20029) and ISE-PIC that could allow authenticated administrators to read arbitrary files; proof-of-concept exploit code is publicly available though Cisco found no evidence of active exploitation. The advisory recommends installing the fixed releases (patches listed per version) and notes other recent Cisco advisories, prior exploited ISE zero-days, and activity by a Chinese-linked group (UAT-9686) against other Cisco products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
