ZeroHour
Product

Cisco ISE Passive Identity Connector

5 mentions in 7 days · 5 in 30 days · 5 total · first seen · last

Timeline

Cisco Identity Services Engine Multiple Path Traversal Vulnerabilities

Cisco ISE and ISE-PIC contain multiple path traversal vulnerabilities allowing remote attacks; fixes released with no workarounds available.

Multiple path traversal vulnerabilities in Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to conduct path traversal attacks on affected devices. Cisco has released software updates that address these vulnerabilities, and no workarounds are available. The advisory is part of a grouped set of September 2026 ISE advisories.

Cisco Security Advisories · 11h agoAdvisory 15 sources

Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Cisco fixed multiple authentication bypass flaws in Identity Services Engine and ISE-PIC enabling remote data access, manipulation, and certificate material disruption.

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on affected devices. Cisco has released software updates, and no workarounds are available. The advisory is part of Cisco's September 2026 publication batch.

Cisco Security Advisories · 11h agoAdvisory 15 sources

Cisco Identity Services Engine SQL and HQL Injection Vulnerabilities

Cisco fixed multiple authenticated SQL and HQL injection flaws in Identity Services Engine and ISE-PIC APIs allowing arbitrary database queries and unauthorized data access.

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and ISE-PIC stem from insufficient validation of user-supplied input to affected APIs before it is used to build database queries. An authenticated, remote attacker can send crafted requests to execute arbitrary SQL or HQL queries against the underlying database, viewing or modifying data they are not authorized to access. Cisco has released software updates.

Cisco Security Advisories · 11h agoAdvisory 15 sources

Cisco Identity Services Engine Hardening Release: September 2026

Cisco ISE hardening release fixes multiple internally discovered vulnerabilities, including an authentication bypass known to be actively exploited.

Cisco released September 2026 hardening updates for Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) following a comprehensive internal security review that uncovered multiple vulnerabilities. One of the flaws, an ISE authentication bypass, is known to be actively exploited. Cisco grouped the issues by underlying vulnerability to help customers prioritize patching and streamline disclosure.

Cisco Security Advisories · 11h agoAdvisory in the wild 15 sources

Cisco Identity Services Engine Command Injection Vulnerabilities

Authenticated attackers with admin credentials could exploit Cisco ISE command injection flaws to execute arbitrary commands as root; fixes released.

Multiple command injection vulnerabilities in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as the root user. Cisco has released software updates, and no workarounds are available. The advisory is part of a grouped set of September 2026 ISE advisories.

Cisco Security Advisories · 11h agoAdvisory 15 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.