Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
identity-authentication-vulnerabilitywidely-deployed-product-advisoryproof-of-concept-releaseinternet-facing-service-vulnerability

Cisco ISE Flaws Expose Authentication Bypass, Root RCE, and Path Traversal

Updated 28d agoFirst seen Apr 15, 20264 sources

Cisco disclosed multiple vulnerabilities in Identity Services Engine (ISE) and ISE-PIC that could let attackers compromise deployments through authentication bypass, unauthenticated remote code execution, and path traversal. One of the issues, tracked as CVE-2025-20281, was described in public research as allowing unauthenticated attackers to achieve remote code execution as root because of insufficient input validation in a specific API, significantly raising the risk to exposed management infrastructure.

Separate Cisco advisories also detailed additional authentication bypass weaknesses and a combination of remote code execution and path traversal flaws affecting the same product line, indicating broad attack surface concerns in enterprise identity and access control environments. The publication of a public GitHub checker for CVE-2025-20281 increases the likelihood of rapid defender validation and potential attacker reconnaissance, making prompt patching, exposure review, and monitoring of Cisco ISE systems a priority for security teams.

Share:
Cisco ISE Flaws Expose Authentication Bypass, Root RCE, and Path Traversal
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
May 6, 20262mo ago

Cisco publishes advisory for ISE authentication bypass vulnerabilities

Cisco issued a security advisory covering authentication bypass vulnerabilities affecting Cisco Identity Services Engine. The advisory publicly documented the issue and associated remediation guidance.

Apr 15, 20262mo ago

Cisco publishes advisory for ISE RCE and path traversal flaws

Cisco released a security advisory for Cisco Identity Services Engine covering remote code execution and path traversal vulnerabilities. The advisory formally disclosed the flaws and provided vendor guidance for affected deployments.

Jul 3, 20251y ago

PoC scanner for CVE-2025-20281 is published on GitHub

A GitHub repository by grupooruss published a script to check Cisco Identity Services Engine (ISE) and ISE-PIC instances for CVE-2025-20281, described as an unauthenticated remote code execution vulnerability allowing root-level compromise due to insufficient input validation in an API.

Jan 8, 20251y ago

Cisco publishes advisory for ISE unauthenticated RCE vulnerabilities

Cisco issued a security advisory for Cisco Identity Services Engine covering unauthenticated remote code execution vulnerabilities. The advisory publicly disclosed the flaws and provided vendor guidance for affected deployments.

Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.