Cisco warns of max severity RCE flaws in Identity Services Engine
ID: 7b85a307-51e9-5e6d-8d95-0da9cf1fe0a6
STIX ID: report--7b85a307-51e9-5e6d-8d95-0da9cf1fe0a6
Feed Name: Bleeping Computer
Threat Score
Cisco published advisories for two critical unauthenticated RCE vulnerabilities in Cisco Identity Services Engine (CVE-2025-20281 and CVE-2025-20282; CVSS 10.0) that allow remote attackers to execute commands as root or upload and run arbitrary files, impacting ISE 3.3/3.4 branches; patches are available and no mitigations were provided. A separate medium-severity SAML-related auth bypass (CVE-2025-20264) is also noted with fixes in recent patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
