Cisco ISE Needs Release-by-Release Patch Verification

Cisco’s two ISE flaws are separate problems, so fixing one build does not mean the other exposure is gone. The usual one-patch-one-bug assumption fails here, especially in environments that run multiple ISE releases. Cisco says CVE-2026-20195 and CVE-2026-20193 are not dependent on one another. A release affected by one may not be affected by the other, and Cisco has released software updates with no workarounds for either flaw. That makes patch status a release-by-release question, not a single advisory checkbox. The residual risk is simple: partial coverage can leave a live bypass in place even after a supposed fix.

Part of the PlainSec briefing for 2026-05-07

Sources