Cisco ISE Flaws Expose Networks to RCE and Sensitive Data Disclosure
Cisco disclosed two vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), including the critical remote code execution flaw CVE-2026-20181 and the high-severity information disclosure flaw CVE-2026-20190. Cisco said CVE-2026-20181 carries a CVSS score of 9.1 and can let an authenticated attacker with valid administrative credentials execute arbitrary commands, obtain user-level access, potentially escalate privileges to root, and in single-node deployments trigger a denial-of-service condition. The second flaw, rated 7.5, can allow an unauthenticated attacker to access sensitive information such as hashed credentials because of improper authorization checks.
The affected software includes all releases prior to 3.3, versions before 3.3 Patch 11 in release 3.3, versions before 3.4 Patch 6 in release 3.4, and versions before 3.5 Patch 4 in release 3.5, according to the Canadian Centre for Cyber Security notice summarizing Cisco’s advisories. Cisco said the vulnerabilities are independent, no workarounds are available, and no confirmed exploitation had been reported at disclosure time. Authorities urged administrators to review Cisco’s advisories and apply the available updates immediately.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
2 events from the most recent confirmed update back to the earliest known activity.
Cisco releases patches for affected ISE and ISE-PIC versions
Cisco released security updates for affected products on 2026-06-17, directing customers to upgrade from vulnerable releases to fixed versions including ISE 3.3 Patch 11, 3.4 Patch 6, and 3.5 patched releases. The advisories covered all releases prior to 3.3 and specified patched versions for the 3.3, 3.4, and 3.5 branches.
Cisco discloses two Cisco ISE and ISE-PIC vulnerabilities
On 2026-06-17, Cisco publicly disclosed two vulnerabilities affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC): CVE-2026-20181, a critical authenticated remote code execution flaw, and CVE-2026-20190, a high-severity information disclosure flaw. Cisco said the issues are independent, no workarounds are available, and there was no confirmed exploitation at the time of disclosure.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
7 references tracked. Mallory keeps watching after this page renders.
Cisco fixed a critical ISE vulnerability that lets attackers to gain root access
securityaffairs.com
Open sourceCisco ISE Vulnerability Allow Attacker to Execute Malicious Code Remotely
cybersecuritynews.com
Open sourceCritical Command Execution Vulnerability Patched in Cisco ISE - SecurityWeek
securityweek.com
Open sourceCisco ISE Vulnerabilities: Critical RCE & Data Risks
securityonline.info
Open sourceCisco security advisory (AV26-613) - Canadian Centre for Cyber Security
cyber.gc.ca
Open sourceCVE-2026-20181 - Cisco Identity Services Engine Remote Code Execution Vulnerability
cvefeed.io
Open sourceCisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities
sec.cloudapps.cisco.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


