HomeUpdatesCisco fixes vulnerability in ISE after PoC exploit published

Cisco patches vulnerability in ISE after PoC exploit published

Cisco has released security updates to address a vulnerability in the Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC). This is a medium severity vulnerability, for which a proof-of-concept (PoC) exploit has been publicly released .

Cisco ISE

The vulnerability, tracked as CVE-2026-20029 (CVSS score: 4.9), is located in the licensing feature and could allow an authorized, remote attacker with administrative privileges to gain access to sensitive information.

See also: Vulnerability in Linux battery tool allows changing system settings

Cisco said that this vulnerability is due to improper parsing of XML, which is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application.

Successful exploitation could allow an attacker with valid administrative credentials to read arbitrary files from the underlying operating system, (which should be inaccessible even to administrators).

See also: Critical n8n vulnerability allows complete control to hackers

Bobby Gould from the Trend Micro Zero Day Initiative was the one who discovered and reported the vulnerability.

Cisco patches vulnerability in ISE after PoC exploit published

Cisco vulnerability: Which software versions are affected?

– Cisco ISE or ISE-PIC Release before 3.2 – Upgrade to a fixed version

– Cisco ISE or ISE-PIC Release 3.2 – 3.2 Patch 8

– Cisco ISE or ISE-PIC Release 3.3 – 3.3 Patch 8

– Cisco ISE or ISE-PIC Release 3.4 – 3.4 Patch 4

– Cisco ISE or ISE-PIC Release 3.5 – Not vulnerable

Cisco stated that there are no other solutions to address the vulnerability. Therefore, applied security updates, given that a PoC exploit is also available.

See also: CISA: Microsoft Office and HPE OneView vulnerabilities in the KEV Catalog

Cisco patches vulnerability in ISE after PoC exploit published

Cisco: Patches for other vulnerabilities

Additionally, Cisco has released fixes for two other medium severity vulnerabilities that arise from the processing of Distributed Computing Environment Remote Procedure Call (DCE/RPC) requests. They could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information .

Trend Micro researcher Guy Lederfeinidentified these two vulnerabilities:

– CVE-2026-20026 (CVSS score: 5.8) – Snort 3 DCE/RPC denial-of-service

– CVE-2026-20027 (CVSS score: 5.3) – Snort 3 DCE/RPC information disclosure vulnerability

Vulnerabilities in Cisco products are often targeted by malicious actors, so users should update to the latest version for adequate protection.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS