ISE-PIC Patch Paths Now Depend on Version

Cisco’s fix is no longer a generic “apply the update” note. The operational problem is that remediation now depends on the exact ISE or ISE-PIC release, and some ISE-PIC users are already on the last supported branch, so patching may require a migration path instead of an in-place update. The exposure boundary is still not fully settled either, because Cisco says CVE-2026-20181 needs valid admin credentials, while NCSC-NL says some of the issues can also be used without authentication. Cisco and the CERTs now publish version-specific fixes: ISE versions before 3.3 need migration for CVE-2026-20181, 3.3 needs Patch 11, 3.4 needs Patch 6 for both CVEs, and 3.5 needs Patch 4 for CVE-2026-20181 and Patch 3 for CVE-2026-20190. INCIBE says ISE-PIC 3.4 is the last supported version, which makes end-of-sale support the key wrinkle for operators who cannot just patch in place.

Part of the PlainSec briefing for 2026-06-19

Every edition of this story: ISE-PIC Patch Paths Now Depend on Version

Sources