Skip to content
Critical Cisco ISE Vulnerabilities Expose Systems to SQL Injection and Command Execution

Critical Cisco ISE Vulnerabilities Expose Systems to SQL Injection and Command Execution

First seen 17 Sep 2026, 16:29 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 18:24 UTC
  • CVE-2026-20300 allows SQL injection via crafted requests.
  • CVE-2026-20307 enables remote command execution through insecure deserialization.
  • Immediate remediation is recommended for affected Cisco ISE systems.

Two vulnerabilities in Cisco Identity Services Engine (ISE) have been disclosed: CVE-2026-20300 and CVE-2026-20307. CVE-2026-20300 allows authenticated attackers to conduct SQL injection attacks, potentially exposing sensitive data and altering network policies. CVE-2026-20307 enables remote command execution through insecure deserialization, risking denial of service and privilege escalation. Both vulnerabilities require low-privileged administrative credentials for exploitation. Organizations with exposed management interfaces are particularly at risk. No active exploitation has been confirmed, but remediation is strongly advised. Cisco has published a fixed software release for these vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
CVE-2026-20300 published
Cisco disclosed a SQL injection vulnerability in Cisco ISE affecting authenticated users.
Redpacketsecurity
2026-09-16
CVE-2026-20307 published
Cisco disclosed a command execution vulnerability in Cisco ISE due to insecure deserialization.
Sploitus
2026-09-17
Remediation recommended
Cisco advises organizations to apply the fixed software release and restrict management access.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-20300 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed