Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Mindgard Raises $30M to Secure AI Systems Against Emerging Threats
August 12, 2026
City-Forum Hackers Exploit Salesforce, ServiceNow Critical Vulnerabilities
August 12, 2026
Palo Alto Networks Patches 11 Vulnerabilities in PAN-OS, GlobalProtect, Prisma Access
August 12, 2026
Home/CyberSecurity News/Critical Cisco ISE Bug (CVE-2023-20100) Lets Attackers Remotely Execute Code
CyberSecurity News

Critical Cisco ISE Bug (CVE-2023-20100) Lets Attackers Remotely Execute Code

Key Takeaways Cisco has disclosed two critical vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The most severe flaw, CVE-2026-20181, allows...

Marcus Rodriguez
Marcus Rodriguez
June 18, 2026 3 Min Read
71 0

Key Takeaways

  • Cisco has disclosed two critical vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC).
  • The most severe flaw, CVE-2026-20181, allows authenticated attackers to achieve remote code execution (RCE) with administrative privileges.
  • The second vulnerability, CVE-2026-20190, permits unauthenticated attackers to disclose sensitive information, including hashed credentials.
  • All versions of Cisco ISE and ISE-PIC are affected, with fixes available in ISE 3.3 Patch 11 and ISE 3.4 Patch 6, and a patch for ISE 3.5 Patch 4 expected in August 2026.
  • No workarounds exist; immediate patching or migration to supported versions is the only effective mitigation.

Cisco ISE Plagued by Critical RCE and Information Disclosure Flaws

Cisco has issued an urgent security advisory regarding critical vulnerabilities discovered within its Identity Services Engine (ISE), a cornerstone for network access control in many enterprise environments. These flaws, which include remote code execution (RCE) and sensitive information disclosure, present significant risks, potentially allowing attackers to compromise networks and access critical data.

Table Of Content

  • Key Takeaways
  • Cisco ISE Plagued by Critical RCE and Information Disclosure Flaws
  • Remote Code Execution via CVE-2026-20181
  • Information Disclosure Through CVE-2026-20190
  • What You Should Do

The vulnerabilities, identified as CVE-2026-20181 and CVE-2026-20190, were officially disclosed on June 17, 2026, under advisory ID cisco-sa-ise-multi-G5WP8vv. Both issues carry a high CVSS score of 9.1, indicating severe impact. The vulnerabilities affect all deployments of Cisco ISE and ISE Passive Identity Connector (ISE-PIC), irrespective of their specific configurations.

Remote Code Execution via CVE-2026-20181

The more critical of the two, CVE-2026-20181, is a remote code execution vulnerability stemming from inadequate validation of user-supplied input. An attacker with existing administrative authentication can exploit this flaw by submitting a specially crafted HTTP request to the vulnerable system.

Successful exploitation grants the attacker the ability to execute arbitrary commands on the underlying operating system. This could initially provide user-level access, which can then be escalated to root privileges, leading to full control over the compromised device. In single-node ISE deployments, successful exploitation can also trigger a denial-of-service (DoS) condition, preventing new endpoints from authenticating until the system is restored. Such a disruption could cripple enterprise access control mechanisms reliant on Cisco ISE.

Information Disclosure Through CVE-2026-20190

The second vulnerability, CVE-2026-20190, is an information disclosure flaw caused by improper authorization checks. Unlike the RCE vulnerability, this issue can be exploited by an unauthenticated remote attacker. By sending crafted requests, an attacker can gain access to sensitive data stored on the device, including hashed credentials. These compromised credentials could then be utilized for further malicious activities, facilitating lateral movement and deeper penetration within the network.

Cisco has confirmed that all versions of ISE and ISE-PIC are impacted, though the specific vulnerabilities may vary depending on the release. Patches have been released for ISE 3.3 Patch 11 and ISE 3.4 Patch 6. A fix for ISE 3.5 Patch 4 is anticipated in August 2026. For earlier versions, migration to a supported release is mandatory, as no workarounds are available, making software updates the only viable mitigation strategy.

Cisco’s Product Security Incident Response Team (PSIRT) has stated that there is no evidence of active exploitation of these vulnerabilities in the wild. However, given their high severity and the relative ease of exploitation, organizations are strongly urged to prioritize and apply the necessary updates without delay. The vulnerabilities were reported through coordinated efforts by security researchers from TrendAI, STAR Labs, and the Zero Day Initiative, underscoring the importance of responsible disclosure.

What You Should Do

  • Immediately assess your Cisco ISE and ISE-PIC deployments for exposure to CVE-2026-20181 and CVE-2026-20190.
  • Upgrade to the latest patched versions: ISE 3.3 Patch 11 or ISE 3.4 Patch 6.
  • If running ISE 3.5, plan to apply Patch 4 once it becomes available in August 2026.
  • For any unsupported versions, initiate a migration plan to a patched, supported release, as no workarounds are available.
  • Restrict administrative access to Cisco ISE instances only from trusted and secured networks.
  • Implement robust log monitoring for suspicious HTTP requests and any unusual authentication or privilege escalation activities on your ISE systems.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

F5 Patches Critical NGINX Vulnerability CVE-2023-50438

Next Post

Critical Microsoft Fondue.exe flaw lets attackers execute malware

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Chrome 115 Patches Five High-Severity Use-After-Free Flaws
August 12, 2026
Eclipse Ransomware Launches RaaS, Targets Windows, Linux, ESXi
August 12, 2026
WhatsApp launches new scam alert feature to combat social engineering
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us