Redpacketsecurity Critical Cisco ISE Vulnerabilities Expose Systems to SQL Injection and Command Execution
Article Content
- •CVE-2026-20300 allows SQL injection via crafted requests.
- •CVE-2026-20307 enables remote command execution through insecure deserialization.
- •Immediate remediation is recommended for affected Cisco ISE systems.
Two vulnerabilities in Cisco Identity Services Engine (ISE) have been disclosed: CVE-2026-20300 and CVE-2026-20307. CVE-2026-20300 allows authenticated attackers to conduct SQL injection attacks, potentially exposing sensitive data and altering network policies. CVE-2026-20307 enables remote command execution through insecure deserialization, risking denial of service and privilege escalation. Both vulnerabilities require low-privileged administrative credentials for exploitation. Organizations with exposed management interfaces are particularly at risk. No active exploitation has been confirmed, but remediation is strongly advised. Cisco has published a fixed software release for these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-20300 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…