ZeroHour
Cisco Security Advisoriespublished ()ingested
Part of a story covered by 15 sources: “Cisco September 2026 ISE Hardening Release Patches Actively Exploited Authentication Bypass and Multiple RCE, Injection, and DoS Flaws” — merged summary and timeline →

Cisco Identity Services Engine Vulnerabilities

mediumAdvisoryimportance 48
AI summary · glm-5.3-flash

Cisco patched ISE and ISE-PIC flaws enabling REST API authentication bypass, remote code execution, SQL injection, and XXE attacks.

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks. Cisco has released software updates; no workarounds address these vulnerabilities.

  • Remote attacker can bypass REST API authentication on ISE and ISE-PIC
  • Flaws also allow RCE, SQL injection, and XXE attacks
  • Software updates released; no workarounds available
Full article

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following…

This source does not provide full text. Read it at sec.cloudapps.cisco.com.