Cisco Identity Services Engine Command Injection Vulnerabilities
Authenticated attackers with admin credentials could exploit Cisco ISE command injection flaws to execute arbitrary commands as root; fixes released.
Multiple command injection vulnerabilities in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as the root user. Cisco has released software updates, and no workarounds are available. The advisory is part of a grouped set of September 2026 ISE advisories.