ZeroHour

CVE-2026-20130

large

Critical unauthenticated injection flaws in Cisco ISE and ISE-PIC (CVSS 10.0)

CVSS 3.1
10.0 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-20130 covers a set of internally discovered improper neutralization of special elements issues (CWE-74, the injection class of weaknesses) in Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC), found during a comprehensive internal security review and addressed in a software hardening release. Per the CVSS vector, the flaws are remotely exploitable by an unauthenticated attacker with no user interaction required (AV:N/AC:L/PR:N). Successful exploitation carries high impact on confidentiality, integrity, and availability with scope change, meaning an attacker could potentially break out beyond the vulnerable component to compromise additional system scope. Any organization running Cisco ISE or ISE-PIC for network access control or passive identity services is potentially affected. There is currently no known exploitation, no public proof-of-concept, and the flaw is not listed in CISA's KEV.

What to do: Apply the Cisco ISE software hardening release referenced in the PSIRT advisory as soon as practical, checking the advisory for the exact fixed release for your ISE/ISE-PIC train since versions are not specified here. In the interim, restrict administrative and API-facing interfaces of ISE (Admin portal, pxGrid, related services) to trusted management networks and review logs for unexpected unauthenticated requests. Include hosts running ISE-PIC (typically Windows domain controllers) in the patch and monitoring plan.

Affected
Cisco Identity Services Engine (ISE)
Cisco ISE Passive Identity Connector (ISE-PIC)
Estimated exposure
largeLikely on the order of tens of thousands of enterprise/public-sector deployments of Cisco ISE, with internet-exposed instances expected to be a much smaller… — Cisco ISE is a long-standing flagship enterprise NAC/identity platform with a broad installed base, but it is typically deployed on internal networks as a policy server (with ISE-PIC connectors on domain controllers), so the number of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20130 are related to improper neutralization of special elements issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.

Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.