logo

Cisco warns of max severity RCE flaws in Identity Services Engine

ID: 7b85a307-51e9-5e6d-8d95-0da9cf1fe0a6

STIX ID: report--7b85a307-51e9-5e6d-8d95-0da9cf1fe0a6

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-06-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Cisco published advisories for two critical unauthenticated RCE vulnerabilities in Cisco Identity Services Engine (CVE-2025-20281 and CVE-2025-20282; CVSS 10.0) that allow remote attackers to execute commands as root or upload and run arbitrary files, impacting ISE 3.3/3.4 branches; patches are available and no mitigations were provided. A separate medium-severity SAML-related auth bypass (CVE-2025-20264) is also noted with fixes in recent patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.