NCSC-2026-0208 [1.00] [M/H] Vulnerabilities fixed in Cisco Identity Services Engine
Cisco has fixed multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). The vulnerabilities can be exploited by both authenticated and unauthenticated attackers. An authenticated attacker with administrative rights can send specially crafted HTTP requests to execute arbitrary commands, potentially leading to Denial-of-Service and privilege escalation, compromising the integrity and availability of the systems. Additionally, some vulnerabilities can lead to unauthorized information disclosure. Unauthenticated attackers can also execute arbitrary code remotely and access sensitive information such as hashed login credentials. The cause lies in improper authorization controls when accessing certain resources within the systems.
CSIRTS triage
- What
- Multiple vulnerabilities in Cisco Identity Services Engine can lead to remote code execution and privilege escalation.
- Who is affected
- Deployments of Cisco Identity Services Engine and ISE-PIC are affected.
- Urgency
- Remediation is critical due to the potential for severe security breaches.
- Action
- Update to the latest version of Cisco Identity Services Engine.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Cisco Identity Services Engine
Get an email when a new Cisco Identity Services Engine advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0208
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-201810.75% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-201900.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20181 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20190 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21