ZeroHour
Cisco Security Advisoriespublished ()ingested
Part of a story covered by 15 sources: “Cisco September 2026 ISE Hardening Release Patches Actively Exploited Authentication Bypass and Multiple RCE, Injection, and DoS Flaws” — merged summary and timeline →

Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities

AI summary · glm-5.3-flash

Cisco fixed ISE vulnerabilities enabling authenticated SQL injection and OS command execution; CVE-2026-20282 and CVE-2026-20283 rated High.

Multiple Cisco Identity Services Engine vulnerabilities allow an authenticated remote attacker to conduct SQL injection, modify data, or execute arbitrary commands on the underlying OS. Cisco assigned a Security Impact Rating of High to CVE-2026-20282 and CVE-2026-20283 because attackers can easily reach root from the achieved privilege level. Software updates are available and a workaround addresses one of the vulnerabilities.

  • Authenticated attackers can perform SQL injection and execute OS commands
  • CVE-2026-20282 and CVE-2026-20283 rated High due to easy root escalation
  • Updates released; workaround available for one vulnerability

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20282

NVD description · AI analysis pending
CVE-2026-20283

NVD description · AI analysis pending
Full article

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct SQL injections, modify data, or execute arbitrary commands on the underlying operating system on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Note: For CVE-2026-20282 and CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the scores indicate. The reason is that it is easy to get to root from the achieved privilege level. Cisco has released software updates that address these vulnerabilities. There are workarounds that address one of these vulnerabilities. This…

This source does not provide full text. Read it at sec.cloudapps.cisco.com.