Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv Security Impact Rating: Critical CVE: CVE-2026-20181,CVE-2026-20190
CSIRTS triage
- What
- Multiple vulnerabilities could allow remote code execution or information disclosure.
- Who is affected
- Deployments of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC).
- Urgency
- Remediation is critical as the vulnerabilities are severe, although not currently exploited.
- Action
- Update to the latest software versions provided by Cisco.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Identity Services Engine
Get an email when a new Identity Services Engine advisory drops — max one per day, one-click unsubscribe.
Details
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-201810.75% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-201900.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20181 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20190 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Cisco Identity Services
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilitiescisco-psirt · 2026-07-20
- medium[NEW] [medium] Cisco Identity Services Engine (ISE): Vulnerability allows file manipulationcert-bund · 2026-07-16
- mediumCVE-2026-20146: A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connect…nvd · 2026-07-15
- mediumCisco Identity Services Engine Path Traversal Vulnerabilitycisco-psirt · 2026-07-15
- unknownNCSC-2026-0208 [1.00] [M/H] Vulnerabilities fixed in Cisco Identity Services Enginencsc-nl · 2026-06-19
- mediumCisco Identity Services Engine Authentication Bypass Vulnerabilitiescisco-psirt · 2026-05-06
More from Cisco Security Advisories
- criticalCisco Crosswork Security Hardening Release: August 20262026-08-21
- criticalCisco Advance Notification for Publication of August 19, 2026, Security Advisories2026-08-19
- mediumCisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forge…2026-08-19
- highCisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability2026-08-19
- criticalCisco Secure Workload Software Security Hardening Release: August 20262026-08-19