Critical Unauthenticated RCE Flaws Patched in Cisco ISE and ISE-PIC
Cisco disclosed two critical vulnerabilities in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that allow unauthenticated remote attackers to execute arbitrary code on the underlying operating system with root privileges. The flaws, tracked as CVE-2025-20281 and CVE-2025-20282, are independent issues, meaning exploitation of one is not required to exploit the other.
CVE-2025-20281 affects Cisco ISE and ISE-PIC version 3.3 and later, while CVE-2025-20282 affects version 3.4 only; Cisco said version 3.2 and earlier are not affected. Cisco also warned that CVE-2025-20282 can enable arbitrary file upload and execution on vulnerable devices. Patches have been released, and organizations running affected deployments have been urged to update immediately.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
2 events from the most recent confirmed update back to the earliest known activity.
Cisco releases patches for affected ISE and ISE-PIC versions
Cisco released fixes for the vulnerabilities and advised organizations to update immediately. CVE-2025-20281 affects ISE and ISE-PIC versions 3.3 and later, while CVE-2025-20282 affects version 3.4; version 3.2 and earlier are not affected.
Cisco discloses critical RCE flaws in ISE and ISE-PIC
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) were found to contain two critical vulnerabilities, CVE-2025-20281 and CVE-2025-20282. The flaws allow unauthenticated remote code execution as root, with CVE-2025-20282 also enabling arbitrary file upload and execution on affected devices.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
Kriittisiä haavoittuvuuksia Cisco Identity Services Engine- ja Cisco ISE Passive Identity Connector -tuotteissa | Traficom
kyberturvallisuuskeskus.fi
Open sourceKriittisiä haavoittuvuuksia Cisco Identity Services Engine- ja Cisco ISE Passive Identity Connector -tuotteissa | Traficom
kyberturvallisuuskeskus.fi
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


