CVE-2026-20195
CVSS 5.3 MEDIUM: a vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker…
Vulnerabilities & Exploits · Web App Attack
Cisco’s two ISE flaws are separate problems, so fixing one build does not mean the other exposure is gone. The usual one-patch-one-bug assumption fails here, especially in environments that run multiple ISE releases.
Cisco says CVE-2026-20195 and CVE-2026-20193 are not dependent on one another. A release affected by one may not be affected by the other, and Cisco has released software updates with no workarounds for either flaw.
That makes patch status a release-by-release question, not a single advisory checkbox. The residual risk is simple: partial coverage can leave a live bypass in place even after a supposed fix.
1 source · May 6
CVSS 5.3 MEDIUM: a vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker…
CVSS 4.3 MEDIUM: a vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker…
Cisco PSIRT
Cisco Security Advisory: Cisco Identity Services Engine Authentication Bypass Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to bypass authorization mechanisms or examine error messages to gain access to sensitive information on an affected device.
originalCisco PSIRT
Cisco Security Advisory: Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
originalPart of the PlainSec briefing for 2026-05-07
Every edition of this story: Cisco ISE Needs Release-by-Release Patch Verification