ZeroHour

CVE-2026-20237

large

Critical Input Validation Flaws in Cisco Identity Services Engine (ISE) and ISE-PIC

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-20237 bundles multiple improper input validation flaws (CWE-20) that Cisco engineers discovered internally during a proactive security review of Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC). The flaws are triggered by sending crafted input to affected network services, and the CVSS vector indicates an attacker must already hold high-privilege access (such as administrative credentials), with no user interaction required. The scope-changed, critical-rated vector (9.1) implies successful exploitation crosses a security boundary—potentially escaping the intended administrative context—with high impact on confidentiality, integrity, and availability of the appliance. Any organization running Cisco ISE or ISE-PIC as its network access control or identity policy platform is potentially affected. No public proof-of-concept, CISA KEV listing, or known exploitation has been reported; the issues are addressed in a proactive software hardening release.

What to do: Update Cisco ISE and ISE-PIC to the hardening release that addresses CVE-2026-20237 as soon as practical, checking the Cisco PSIRT advisory for the exact fixed version for your release train. Until patched, restrict administrative (high-privilege) access to ISE/ISE-PIC to trusted management networks and audit privileged account usage, since exploitation requires high privileges. Because no exploitation is known and details are limited, monitor Cisco PSIRT for updates and additional affected version information.

Affected
Cisco Identity Services Engine (ISE)
Cisco ISE Passive Identity Connector (ISE-PIC)
Estimated exposure
large≈10,000–100,000 ISE/ISE-PIC deployments worldwide (typically enterprise/government clusters, mostly internally hosted) — Cisco ISE is one of the most widely deployed enterprise network access control/policy platforms, generally run by large organizations and government agencies on internal management networks; Cisco does not publish install counts, so this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20237 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.

Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.