CVE-2026-20181
CVSS 9.1 CRITICAL: a vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. EPSS 9% (95th percentile), up from 0.7%.
Vulnerabilities · 87 days ago
Cisco’s fix is no longer a generic “apply the update” note. The operational problem is that remediation now depends on the exact ISE or ISE-PIC release, and some ISE-PIC users are already on the last supported branch, so patching may require a migration path instead of an in-place update. The exposure boundary is still not fully settled either, because Cisco says CVE-2026-20181 needs valid admin credentials, while NCSC-NL says some of the issues can also be used without authentication.
Cisco and the CERTs now publish version-specific fixes: ISE versions before 3.3 need migration for CVE-2026-20181, 3.3 needs Patch 11, 3.4 needs Patch 6 for both CVEs, and 3.5 needs Patch 4 for CVE-2026-20181 and Patch 3 for CVE-2026-20190. INCIBE says ISE-PIC 3.4 is the last supported version, which makes end-of-sale support the key wrinkle for operators who cannot just patch in place.
CVSS 9.1 CRITICAL: a vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. EPSS 9% (95th percentile), up from 0.7%.
CVSS 7.5 HIGH: a vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive… EPSS 0.5% (40th percentile).
5 sources covering this story
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected device.
Múltiples vulnerabilidades en ISE e ISE-PIC de CISCO
CISCO ha publicado un aviso donde informan de dos vulnerabilidades, una de severidad crítica y otra al
Kwetsbaarheden verholpen in Cisco Identity Services Engine
Cisco heeft meerdere kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE) en Cisco ISE Passive Identity Connector (ISE-PIC).
Critical Command Execution Vulnerability Patched in Cisco ISE
Insufficient validation of user input allows an attacker to gain access to the underlying OS and elevate their privileges to root.
Risolte vulnerabilità in prodotti Cisco
Aggiornamenti di sicurezza risolvono due nuove vulnerabilità, di cui una con gravità “critica” e una con gravità “alta”, in Cisco ISE e Cisco ISE-PIC, noti software per la gestione dell'identità e del controllo degli accessi di rete.
Part of the PlainSec briefing for 2026-06-19