Cisco has updates addressing vulnerabilities across Identity Services Engine (ISE). The updates include flaws that could allow unauthorized access, command execution, remote code execution, SQL injection, authentication bypass, privilege escalation, data modification, and denial-of-service conditions. Three ISE vulnerabilities had already been disclosed, while an access-control vulnerability class contains two flaws that have been exploited in the wild. Cisco also disclosed an ISE authentication-bypass vulnerability that was exploited in the wild.
CVE-2026-20282 (CVSS 4.9 — Medium): A vulnerability in Cisco ISE allows an authenticated remote attacker to obtain write access to the underlying operating system through a crafted HTTP request.[/subscribe_to_unlock_form]
Cisco has updates addressing vulnerabilities across Identity Services Engine (ISE). The updates include flaws that could allow unauthorized access, command execution, remote code execution, SQL injection, authentication bypass, privilege escalation, data modification, and denial-of-service conditions. Three ISE vulnerabilities had already been disclosed, while an access-control vulnerability class contains two flaws that have been exploited in the wild. Cisco also disclosed an ISE authentication-bypass vulnerability that was exploited in the wild.
CVE-2026-20282 (CVSS 4.9 — Medium): A vulnerability in Cisco ISE allows an authenticated remote attacker to obtain write access to the underlying operating system through a crafted HTTP request.[emaillocker id="1283"]
CVE-2026-20283 (CVSS 6.5 — Medium): A vulnerability in Cisco ISE allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system through crafted IPsec Open API input.
The following reports contain further technical details:
[/emaillocker]