Cisco Identity Services Engine Vulnerabilities
Cisco patched ISE and ISE-PIC flaws enabling REST API authentication bypass, remote code execution, SQL injection, and XXE attacks.
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks. Cisco has released software updates; no workarounds address these vulnerabilities.
Cisco Identity Services Engine Multiple Path Traversal Vulnerabilities
Cisco ISE and ISE-PIC contain multiple path traversal vulnerabilities allowing remote attacks; fixes released with no workarounds available.
Multiple path traversal vulnerabilities in Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to conduct path traversal attacks on affected devices. Cisco has released software updates that address these vulnerabilities, and no workarounds are available. The advisory is part of a grouped set of September 2026 ISE advisories.
Cisco Identity Services Engine Authentication Bypass Vulnerabilities
Cisco fixed multiple authentication bypass flaws in Identity Services Engine and ISE-PIC enabling remote data access, manipulation, and certificate material disruption.
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on affected devices. Cisco has released software updates, and no workarounds are available. The advisory is part of Cisco's September 2026 publication batch.
Cisco Identity Services Engine SQL and HQL Injection Vulnerabilities
Cisco fixed multiple authenticated SQL and HQL injection flaws in Identity Services Engine and ISE-PIC APIs allowing arbitrary database queries and unauthorized data access.
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and ISE-PIC stem from insufficient validation of user-supplied input to affected APIs before it is used to build database queries. An authenticated, remote attacker can send crafted requests to execute arbitrary SQL or HQL queries against the underlying database, viewing or modifying data they are not authorized to access. Cisco has released software updates.
Cisco Identity Services Engine Command Injection Vulnerabilities
Authenticated attackers with admin credentials could exploit Cisco ISE command injection flaws to execute arbitrary commands as root; fixes released.
Multiple command injection vulnerabilities in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as the root user. Cisco has released software updates, and no workarounds are available. The advisory is part of a grouped set of September 2026 ISE advisories.