ZeroHour
Cisco Security Advisoriespublished ()ingested
Part of a story covered by 15 sources: “Cisco September 2026 ISE Hardening Release Patches Actively Exploited Authentication Bypass and Multiple RCE, Injection, and DoS Flaws” — merged summary and timeline →

Cisco Identity Services Engine Authentication Bypass Vulnerabilities

mediumAdvisoryimportance 38
AI summary · glm-5.3-flash

Cisco fixed multiple authentication bypass flaws in Identity Services Engine and ISE-PIC enabling remote data access, manipulation, and certificate material disruption.

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on affected devices. Cisco has released software updates, and no workarounds are available. The advisory is part of Cisco's September 2026 publication batch.

  • Remote attacker can access or manipulate data on ISE and ISE-PIC
  • Flaws can expose sensitive information and reload certificate and key material
  • No workarounds available; patching is the only mitigation
  • Part of Cisco's September 2026 advisory group
Full article

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4 This advisory is part of a…

This source does not provide full text. Read it at sec.cloudapps.cisco.com.