Cisco ISE Flaws Expose Authentication Bypass, Root RCE, and Path Traversal
Cisco disclosed multiple vulnerabilities in Identity Services Engine (ISE) and ISE-PIC that could let attackers compromise deployments through authentication bypass, unauthenticated remote code execution, and path traversal. One of the issues, tracked as CVE-2025-20281, was described in public research as allowing unauthenticated attackers to achieve remote code execution as root because of insufficient input validation in a specific API, significantly raising the risk to exposed management infrastructure.
Separate Cisco advisories also detailed additional authentication bypass weaknesses and a combination of remote code execution and path traversal flaws affecting the same product line, indicating broad attack surface concerns in enterprise identity and access control environments. The publication of a public GitHub checker for CVE-2025-20281 increases the likelihood of rapid defender validation and potential attacker reconnaissance, making prompt patching, exposure review, and monitoring of Cisco ISE systems a priority for security teams.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
Cisco publishes advisory for ISE authentication bypass vulnerabilities
Cisco issued a security advisory covering authentication bypass vulnerabilities affecting Cisco Identity Services Engine. The advisory publicly documented the issue and associated remediation guidance.
Cisco publishes advisory for ISE RCE and path traversal flaws
Cisco released a security advisory for Cisco Identity Services Engine covering remote code execution and path traversal vulnerabilities. The advisory formally disclosed the flaws and provided vendor guidance for affected deployments.
PoC scanner for CVE-2025-20281 is published on GitHub
A GitHub repository by grupooruss published a script to check Cisco Identity Services Engine (ISE) and ISE-PIC instances for CVE-2025-20281, described as an unauthenticated remote code execution vulnerability allowing root-level compromise due to insufficient input validation in an API.
Cisco publishes advisory for ISE unauthenticated RCE vulnerabilities
Cisco issued a security advisory for Cisco Identity Services Engine covering unauthenticated remote code execution vulnerabilities. The advisory publicly disclosed the flaws and provided vendor guidance for affected deployments.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
4 references tracked. Mallory keeps watching after this page renders.
Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities
sec.cloudapps.cisco.com
Open sourceCisco Identity Services Engine Authentication Bypass Vulnerabilities
sec.cloudapps.cisco.com
Open sourceGitHub - grupooruss/CVE-2025-20281-Cisco: This script checks for the presence of the **CVE-2025-20281** vulnerability in Cisco Identity Services Engine (ISE) and ISE-PIC, which allows **unauthenticated remote code execution (RCE)** as root due to insufficient input validation in a specific API. · GitHub
github.com
Open sourceCisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
sec.cloudapps.cisco.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


