ZeroHour
Cisco Security Advisoriespublished ()ingested
Part of a story covered by 15 sources: “Cisco September 2026 ISE Hardening Release Patches Actively Exploited Authentication Bypass and Multiple RCE, Injection, and DoS Flaws” — merged summary and timeline →

Cisco Identity Services Engine Remote Code Execution Vulnerabilities

mediumAdvisoryimportance 40
AI summary · glm-5.3-flash

Cisco patched multiple authenticated remote code execution vulnerabilities in Identity Services Engine that require valid administrative credentials.

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) allow an authenticated remote attacker with valid administrative credentials to execute arbitrary commands on the underlying operating system. Cisco has released software updates; no workarounds address these vulnerabilities. The advisory is part of a batch of ISE releases.

  • Authenticated attackers with admin credentials can execute arbitrary OS commands
  • Cisco released software updates; no workarounds available
  • Advisory is part of a larger batch of ISE releases
Full article

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have valid administrative credentials. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57 This advisory is part of a…

This source does not provide full text. Read it at sec.cloudapps.cisco.com.