ZDI-26-717: Cisco Identity Services Engine AlarmMessageDiskQueue Deserialization of Untrusted Data Remote Code Execution Vulnerability
ZDI disclosed CVE-2026-20211, an authenticated deserialization flaw (CVSS 7.2) enabling remote code execution in Cisco Identity Services Engine.
ZDI-26-717 describes a deserialization of untrusted data vulnerability in Cisco Identity Services Engine's AlarmMessageDiskQueue that allows remote code execution. Exploitation requires valid authentication. The flaw is tracked as CVE-2026-20211 with a CVSS score of 7.2.
- Unsafe deserialization in AlarmMessageDiskQueue enables authenticated RCE
- CVSS 7.2; valid credentials required to exploit
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20211 | Authenticated Java Deserialization RCE in Cisco Identity Services Engine (ISE) CVE-2026-20211 is an insecure deserialization flaw (CWE-502) in Cisco Identity Services Engine that stems from the software deserializing untrusted Java objects. An authenticated, remote attacker who already holds valid high-privileged administrative credentials can send a crafted serialized Java object to an affected device, gaining user-level command execution on the underlying operating system and then escalating to root. A compromised node therefore exposes the full ISE appliance, and in single-node deployments exploitation can render the ISE node unavailable, blocking network access for endpoints that have not yet authenticated. All Cisco ISE deployments are potentially affected, though exploitation requires possession of top-tier admin credentials, which materially limits the attacker pool. As of this analysis there is no known public proof-of-concept and the flaw is not listed in CISA's KEV, so exploitation is not known to be occurring. Do: Check the Cisco PSIRT advisory for CVE-2026-20211 and upgrade ISE to the fixed release it specifies for your software train. In the meantime, restrict access to the ISE administration interface to trusted management networks, audit and rotate high-privileged administrator credentials, and monitor appliances for unexpected OS-level or root activity; operators of single-node deployments should plan for a restoration path since exploitation can take the node down. | 9.1 | — |
| largetens of thousands of ISE deployments worldwide (exact counts not published) |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20211.
This source does not provide full text. Read it at zerodayinitiative.com.