Cisco: Maximum-severity ISE RCE flaws now exploited in attacks

Threat Score
69%
5 articles 100.0% Similarity 19 hours ago

Activity Timeline

Cisco Patches Three Critical Vulnerabilities – Her...
TechRepublic Security
Jul 22
00:16
Cisco Warns of Identity Services Engine RCE Vulner...
Cybersecurity News
Jul 22
11:57
Cisco Alerts on ISE RCE Vulnerability Actively Exp...
GB Hackers
Jul 22
12:07
Cisco Confirms Active Exploits Targeting ISE Flaws...
The Hacker News
Jul 22
13:08
Cisco: Maximum-severity ISE RCE flaws now exploite...
BleepingComputer
Primary Article
Jul 22
14:40
Cisco: Maximum-severity ISE RCE flaws now exploited in attacks
  • Cisco has identified three critical remote code execution vulnerabilities (CVE-2025-20281, CVE-2025-20282, CVE-2025-20337) in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), all rated 10.0 on the CVSS scale.
  • These vulnerabilities allow unauthenticated attackers to execute arbitrary commands with root privileges, posing significant risks to network security and access control.
  • Cisco confirmed that these vulnerabilities are actively being exploited in the wild, although specific details about the threat actors or the scale of attacks remain undisclosed.
  • Immediate action is required: organizations must apply the latest security patches provided by Cisco to mitigate these vulnerabilities, as no workarounds are available.

Cisco has issued an urgent advisory regarding three critical remote code execution vulnerabilities (CVE-2025-20281, CVE-2025-20282, CVE-2025-20337) in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), which are currently being exploited by attackers. These flaws allow unauthenticated remote access with root privileges, threatening network integrity and access control. Organizations must urgently apply the latest patches to affected systems to prevent exploitation, as no alternative mitigations exist. Security teams should prioritize these updates to safeguard their networks and monitor for any signs of unauthorized access.

Save to Folder

Choose a folder to save this cluster: