AI analysis
Cisco has disclosed a critical vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), discovered internally during a proactive security review and remediated as part of a software hardening release. The flaw falls under CWE-669 (incorrect resource transfer between spheres), meaning resources or privileges are not properly isolated between security boundaries. Per the CVSS vector, it is remotely triggerable with low attack complexity and no user interaction, but requires an attacker to already hold high privileges (such as admin-level access), and the changed scope indicates a successful exploit crosses a security boundary to compromise components outside the originally trusted context, with high impact to confidentiality, integrity, and availability. Any organization running Cisco ISE or ISE-PIC is potentially affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and no exploitation has been reported.
What to do: Check the Cisco security advisory (assigned by Cisco PSIRT) for the exact affected releases and apply the hardening update for ISE and ISE-PIC as soon as practical. Because exploitation requires high privileges, restrict ISE/ISE-PIC administrative access to trusted management networks, enforce MFA and strong credential hygiene for admin accounts, and review admin audit logs for unexpected privileged activity. Avoid exposing ISE or ISE-PIC interfaces directly to the internet.
Affected
| Cisco Identity Services Engine (ISE) | — |
| Cisco ISE Passive Identity Connector (ISE-PIC) | — |
Estimated exposure
large≈10,000–100,000 enterprise deployments of Cisco ISE/ISE-PIC (public internet scans show thousands of exposed ISE admin interfaces; most deployments are… — Cisco ISE is one of the most widely deployed enterprise NAC/identity policy platforms, with deployments concentrated in large enterprise and government networks, and public scan services list thousands of externally visible ISE instances —…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20194 are related to incorrect resource transfer between spheres that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-669.