Latest Cisco ISE and Cisco ISE-PIC vulnerabilities: #
On September 16, 2026, Cisco published four advisories covering multiple vulnerabilities in ISE and ISE-PIC. All four advisories affect the same 3.1-3.5 release lines and share an identical set of first-fixed releases, so they are combined here into a single Rapid Response with one remediation path. The vulnerabilities are independent of one another; a release affected by one is not necessarily affected by the others.
- CVE-2026-76460 (cisco-sa-ISE-ABP-VNSW7Tn5): An unauthenticated, remote attacker can bypass authentication on an API endpoint due to insufficient authentication control, gaining unauthorized access to the web-based management interface. This vulnerability has been designated CVE-2026-76460 and has been rated critical with a CVSS score of 10.0.
- CVE-2026-76423 (cisco-sa-ise-multi-hrP9jQSQ): An unauthenticated, remote attacker can gain administrative access via the REST API due to insufficient authorization checks on the exposed REST API port. This vulnerability has been designated CVE-2026-76423 and has been rated critical with a CVSS score of 10.0.
- CVE-2026-76424 (cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can upload or copy arbitrary files via the REST API due to insufficient path validation, leading to root command execution. This vulnerability has been designated CVE-2026-76424 and has been rated high with a CVSS score of 7.2.
- CVE-2026-76425 (cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can conduct SQL injection against the backend database and perform SSRF. This vulnerability has been designated CVE-2026-76425 and has been rated high with a CVSS score of 7.6.
- CVE-2026-76426 (cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can conduct SQL injection against the monitoring database via the REST API. This vulnerability has been designated CVE-2026-76426 and has been rated medium with a CVSS score of 4.9.
- CVE-2026-76427 (cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can read arbitrary files via XML external entity injection in the offline profiler feed service. This vulnerability has been designated CVE-2026-76427 and has been rated medium with a CVSS score of 4.9.
- CVE-2026-76428 (cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can conduct SQL injection against the session database via the REST API. This vulnerability has been designated CVE-2026-76428 and has been rated medium with a CVSS score of 4.9.
- CVE-2026-20307 (cisco-sa-ise-rce-se7bYU57): A low-privileged, authenticated attacker can execute arbitrary root-level commands via insecure deserialization of a Java object in the web-based management interface. This vulnerability has been designated CVE-2026-20307 and has been rated critical with a CVSS score of 9.9.
- CVE-2026-20176 (cisco-sa-ise-rce-se7bYU57): A high-privileged, authenticated attacker can execute arbitrary root-level commands due to insufficient input validation. This vulnerability has been designated CVE-2026-20176 and has been rated critical with a CVSS score of 9.1.
- CVE-2026-20211 (cisco-sa-ise-rce-se7bYU57): A high-privileged, authenticated attacker can execute arbitrary root-level commands via insecure deserialization of Java objects. This vulnerability has been designated CVE-2026-20211 and has been rated critical with a CVSS score of 9.1.
Cisco also disclosed a hardening release (cisco-sa-hardening-ise-XU5EwX5T) covering multiple vulnerabilities found during internal security testing. Cisco grouped these by underlying CWE class and assigned one CVE ID per class, so each CVE below represents several related internal findings rather than a single flaw:
- CVE-2026-20130 (cisco-sa-hardening-ise-XU5EwX5T): Improper neutralization of special elements in output (CWE-74), covering command injection, cross-site scripting, XML injection, code injection, and resource injection findings. This vulnerability has been designated CVE-2026-20130 and has been rated critical with a CVSS score of 10.0.
- CVE-2026-20192 (cisco-sa-hardening-ise-XU5EwX5T): Improper access control (CWE-284), covering authorization, authentication, privilege, and bypass findings. This vulnerability has been designated CVE-2026-20192 and has been rated critical with a CVSS score of 10.0.
- CVE-2026-20194 (cisco-sa-hardening-ise-XU5EwX5T): Incorrect resource transfer between spheres (CWE-669), covering exposure of sensitive information in transit, improper removal of sensitive information before storage, and unrestricted file upload findings. This vulnerability has been designated CVE-2026-20194 and has been rated critical with a CVSS score of 9.1.
- CVE-2026-20234 (cisco-sa-hardening-ise-XU5EwX5T): Insufficiently protected credentials (CWE-522), covering information disclosure and passwords stored or encoded in a recoverable format. This vulnerability has been designated CVE-2026-20234 and has been rated critical with a CVSS score of 9.9.
- CVE-2026-20237 (cisco-sa-hardening-ise-XU5EwX5T): Improper input validation (CWE-20), covering path traversal and external control of file paths. This vulnerability has been designated CVE-2026-20237 and has been rated critical with a CVSS score of 9.9.
- CVE-2026-20287 (cisco-sa-hardening-ise-XU5EwX5T): Improper privilege management (CWE-269), covering incorrect privilege assignment, privilege chaining, and misuse of privilege-checking APIs. This vulnerability has been designated CVE-2026-20287 and has been rated medium with a CVSS score of 6.5.
These vulnerabilities affect Cisco ISE and ISE-PIC regardless of device configuration.
There is evidence that CVE-2026-76460 is being actively exploited in the wild, and it was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 16, 2026.
The following releases are affected by one or more of these vulnerabilities:
- Cisco ISE and ISE-PIC 3.1: Versions through 3.1 Patch 11
- Cisco ISE and ISE-PIC 3.2: Versions through 3.2 Patch 10
- Cisco ISE and ISE-PIC 3.3: Versions through 3.3 Patch 11
- Cisco ISE and ISE-PIC 3.4: Versions through 3.4 Patch 6
- Cisco ISE and ISE-PIC 3.5: Versions through 3.5 Patch 3
Cisco ISE Software Release 3.0 has reached End of Software Maintenance; customers are advised to migrate to a supported release that includes the fixes.
What are Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC)? #
Cisco Identity Services Engine (ISE) is a network access control and policy enforcement platform, and Cisco ISE Passive Identity Connector (ISE-PIC) provides passive identity mapping for third-party enforcement devices.
What is the impact? #
Successful exploitation of these vulnerabilities would allow an unauthenticated, remote attacker to completely compromise the system, gain full administrative and root-level control, execute arbitrary code, and compromise the integrity and confidentiality of sensitive network policy and identity data.
Are any updates or workarounds available? #
Users are encouraged to update to the latest version as quickly as possible:
- Cisco ISE and ISE-PIC 3.1: Upgrade to 3.1 Patch 12 or later. This release does not have a fixed release for CVE-2026-76424, CVE-2026-76425, CVE-2026-76426, CVE-2026-76427, or CVE-2026-76428; migrate to 3.3 Patch 12 or later to remediate those.
- Cisco ISE and ISE-PIC 3.2: Upgrade to 3.2 Patch 11 or later. This release does not have a fixed release for CVE-2026-76424, CVE-2026-76425, CVE-2026-76426, CVE-2026-76427, or CVE-2026-76428; migrate to 3.3 Patch 12 or later to remediate those.
- Cisco ISE and ISE-PIC 3.3: Upgrade to 3.3 Patch 12 or later.
- Cisco ISE and ISE-PIC 3.4: Upgrade to 3.4 Patch 7 or later.
- Cisco ISE and ISE-PIC 3.5: Upgrade to 3.5 Patch 4 or later.
Cisco ISE-PIC has reached the end-of-sale date; release 3.4 is the last supported release.
There are no workarounds. As a temporary mitigation, use infrastructure access control lists (iACLs) to allow only required management and control plane traffic destined to the affected device.
How do I find Cisco ISE installations with runZero? #
From the Software Inventory, use the following query to locate potentially impacted installations:
vendor:="Cisco" AND product:="Identity Services Engine"
July 2025: CVE-2025-20281, CVE-2025-20282, and CVE-2025-20337 #
Three vulnerabilities have been disclosed in certain versions of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that could allow an unauthenticated, remote adversary to issue execute commands on the underlying operating system as the root user. There is evidence that this vulnerability is being actively exploited in the wild.
- Cisco ISE and Cisco ISE-PIC are at risk of an insufficient validation of user-supplied input vulnerability in a specific API. This could allow an unauthenticated, remote adversary to execute arbitrary code on the underlying operating system as the root user via a specially crafted API request. Successful exploitation could allow the adversary to obtain root privileges on an affected device. The adversary does not require any valid credentials to be able to exploit the vulnerability. This vulnerability has been designated CVE-2025-20281 and has been rated critical with a CVSS score of 9.8.
- Cisco ISE and Cisco ISE-PIC are at risk of an improper privilege management vulnerability in an internal API due to a lack of file validation checks to prevent uploaded files from being stored in privileged directories on an affected system. This could allow an unauthenticated, remote adversary to upload arbitrary files to an affected device and then execute those files on the underlying operating system as the root user. Successful exploitation could allow the adversary to store malicious files on an affected system and then execute arbitrary code or obtain root privileges on an affected device. This vulnerability has been designated CVE-2025-20282 and has been rated critical with a CVSS score of 10.0
- Cisco ISE and Cisco ISE-PIC are at risk of an insufficient validation of user-supplied input vulnerability in a specific API. This could allow an unauthenticated, remote adversary to execute arbitrary code on the underlying operating system as the root user via a specially crafted API request. Successful exploitation could allow the adversary to obtain root privileges on an affected device. The adversary does not require any valid credentials to be able to exploit the vulnerability. This vulnerability has been designated CVE-2025-20337 and has been rated critical with a CVSS score of 10.0.
The following versions are affected
- Cisco ISE or ISE-PIC release 3.3 prior to version 3.3 Patch 7
- Cisco ISE or ISE-PIC release 3.4 prior to version 3.4 Patch 2
What is the impact? #
Successful exploitation of this vulnerability by an attacker would allow credentials extracted from a Cisco ISE instance to be used on others from the same release on the same cloud platform. This could allow the attacker to access sensitive data, execute limited administrative operations, modify system configurations or disrupt services within the impacted systems.
Are any updates or workarounds available? #
Cisco has released updates in the form of patches for releases 3.3 and 3.4. Users should update to the latest version of the affected software.
- Cisco ISE or ISE-PIC release 3.3 to version 3.3 Patch 7 and later releases
- Cisco ISE or ISE-PIC release 3.4 to version 3.4 Patch 2 and later releases
Since the initial (version 1.0) advisory publication, Cisco released an improved fix for release 3.3 and recommends upgrading as follows:
- Release 3.3 Patch 6 should be up upgraded to Release 3.3 Patch 7
- Hot patch ise-apply-CSCwo99449_3.3.0.430_patch4-SPA.tar.gz or ise-apply-CSCwo99449_3.4.0.608_patch1-SPA.tar.gz should be up upgraded to Release 3.3 Patch 7 or Release 3.4 Patch 2
How do I find Cisco ISE installations with runZero? #
From the Software Inventory, use the following query to locate potentially impacted installations:
vendor:="Cisco" AND product:="Identity Services Engine"
June 2024: CVE-2025-20286 #
A vulnerability has been disclosed in certain cloud-deployed versions of Cisco Identity Services Engine (ISE) in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI). The vulnerability exists due to improper credential generation in cloud platform deployments resulting in shared credentials across deployments based on release and cloud platform.
It is important to note that Cisco ISE is affected by this vulnerability when the Primary Administration node is deployed in the cloud. An on-premises Primary Administration node is not affected.
The following platforms and versions are affected
- AWS Cisco ISE 3.1, 3.2, 3.3 and 3.4
- Azure Cisco ISE 3.2, 3.3 and 3.4
- OCI Cisco ISE 3.2, 3.3 and 3.4
This vulnerability has been designated CVE-2025-20286 and has a CVSS score of 9.9 (critical).
What is the impact? #
Successful exploitation of this vulnerability by an attacker would allow credentials extracted from a Cisco ISE instance to be used on others from the same release on the same cloud platform. This could allow the attacker to access sensitive data, execute limited administrative operations, modify system configurations or disrupt services within the impacted systems.
Are any updates or workarounds available? #
Cisco has released updates in the form of a hot fix for releases 3.1 through 3.4. Update to the latest version of the affected software when updates are available.