Skip to content
Multiple Vulnerabilities in Cisco Identity Services Engine

Multiple Vulnerabilities in Cisco Identity Services Engine

Csa.Sg • June 19, 2026

Attackers can exploit multiple vulnerabilities in Cisco Identity Services Engine to execute arbitrary commands on the underlying operating system and disclose sensitive information. Patch immediately.

Cisco has released security updates to address a command injection vulnerability (CVE-2026-20181) and an information disclosure vulnerability (CVE-2026-20190) affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC).

The vulnerabilities have Common Vulnerability Scoring System (CVSS v3.1) scores of: CVE-2026-20181 at 9.1 and CVE-2026-20190 at 7.5 out of 10.

Successful exploitation of these vulnerabilities could lead to the following:

- CVE-2026-20181: Due to insufficient validation of user-supplied input, an authenticated attacker with administrative credentials could send a crafted HTTP request to execute arbitrary commands on the underlying operating system, potentially escalating privileges to root.

- CVE-2026-20190: Due to improper authorisation checks when a resource is accessed, an unauthenticated attacker could send crafted traffic to an affected device to gain access to sensitive information, including hashed credentials that could be used in future attacks.

This vulnerability affects Cisco ISE and Cisco ISE-PIC, regardless of device configuration.

Users and administrators of affected products are advised to update to the latest versions immediately.

Cisco ISE-PIC has reached the end-of-sale date. Release 3.4 is the last supported release.

A hot patch for Cisco ISE is available upon request. the Cisco Technical Assistance Center (TAC).

The fixed release for CVE-2026-20181 on Cisco ISE 3.5 (Patch 4) will not be available until August 2026.