ZeroHour

CVE-2026-20192

large1

Critical Improper Access Control Flaws in Cisco ISE and ISE-PIC

CVSS 3.1
10.0 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-20192 tracks a set of improper access control vulnerabilities (CWE-284) in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), discovered by Cisco's own engineering teams during a comprehensive internal security review. The flaws are addressed through a software hardening release rather than an externally reported incident, and Cisco has not disclosed granular per-flaw mechanics in the available data. The CVSS 3.1 score of 10.0 (critical) indicates the issues are remotely exploitable over a network without privileges or user interaction, with high impact to confidentiality, integrity, and availability across security scopes, meaning an attacker could gain broad access or control within affected deployments. All organizations running Cisco ISE or ISE-PIC are potentially affected. There is currently no known exploitation, no public proof-of-concept, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Review Cisco's security advisory (from Cisco PSIRT) to identify which ISE and ISE-PIC releases are affected, and apply the software hardening release as soon as practical. Until patched, restrict access to ISE administration, pxGrid, and passive-identity interfaces to trusted management networks, and monitor Cisco's advisory for updates on exploitation status.

Affected
Cisco Identity Services Engine (ISE)
Cisco ISE Passive Identity Connector (ISE-PIC)
Estimated exposure
largetens of thousands of enterprise ISE/ISE-PIC deployments worldwide, with only a smaller subset exposing management interfaces to untrusted networks — Cisco ISE is a market-leading network access control and identity platform deployed broadly across large enterprises and government networks, but it is typically deployed on internal networks, limiting internet-reachable exposure to a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20192 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.