Cisco is warning that three recently patched critical remote code execution vulnerabilities in the Cisco Identity Services Engine (ISE) are now being actively exploited in attacks.
See also: Cisco patches another critical ISE vulnerability

Although the manufacturer did not specify how the exploit was exploited or whether the attacks were successful, immediate implementation of security updates is now critical. Cisco Identity Services Engine (ISE) is a platform that allows large organizations to control network access and enforce security policies.
The vulnerabilities with the highest severity rating were first disclosed by the company on June 25, 2025 (CVE-2025-20281 and CVE-2025-20282) and on July 16, 2025 (CVE-2025-20337).
A brief description of the vulnerabilities:
CVE-2025-20281: Critical unauthenticated remote code execution in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). An attacker could send modified API requests and execute arbitrary commands as root on the underlying operating system, without requiring authentication. The vulnerability was fixed in ISE versions 3.3 Patch 7 and 3.4 Patch 2.
CVE-2025-20282: Critical uncertified arbitrary file upload and execution vulnerability in Cisco ISE and ISE-PIC version 3.4. Lack of adequate file checking allows malicious files to be sent to privileged folders, which can be executed as root. The vulnerability was fixed in ISE version 3.4 Patch 2.
CVE-2025-20337: Critical uncertified remote code execution vulnerability affecting Cisco ISE and ISE-PIC. Can be exploited via specially crafted API requests due to insufficient login verification, allowing an attacker to gain access without credentials. The vulnerability was fixed in ISE versions 3.3 Patch 7 and 3.4 Patch 2.
See also: Cisco: Unified CM has hardcoded SSH root credentials

All three vulnerabilities have been rated with the maximum severity (CVSS: 10.0) and can be exploited remotely without requiring authentication, making them attractive targets for hackers seeking to gain access to corporate networks.
Cisco had previously released two separate updates (hot patches) for the vulnerabilities, due to the time gap in their discovery. To address all of them simultaneously, the following actions are recommended:
- ISE 3.3 users should upgrade to Patch 7
- ISE 3.4 users should upgrade to Patch 2
- Those using ISE 3.2 or earlier are not affected and do not need to take any action.
See also: Cisco: Critical vulnerabilities in Cisco Identity Services Engine (ISE)
There are no workarounds or interim measures to address these three vulnerabilities — applying the updates is the only recommended solution. Cisco ISE is a key access control tool, so any vulnerability in this system can be used as an entry point for further lateral movement into the network. In short: If your company is using Cisco ISE on the affected versions, applying the patches is not an option — it is a necessity.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
