ZeroHour
Story · 1 source · 15 articlesfirst updated ()

Cisco September 2026 ISE Hardening Release Patches Actively Exploited Authentication Bypass and Multiple RCE, Injection, and DoS Flaws

highAdvisoryexploited in the wildimportance 58CVE-2026-20282CVE-2026-20283
What's new: This is the first merged summary for this story (no prior summary). On 2026-09-16, Cisco moved from vulnerable ISE/ISE-PIC builds to hardened releases, shipping software updates across ten grouped advisories covering authentication bypass (including one actively exploited), RCE/command injection as root, SQL/HQL injection, XXE, data manipulation and certificate/key material reload, RADIUS DoS,…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Cisco released hardening software updates for Identity Services Engine (ISE) and ISE-PIC on 2026-09-16 after an internal security review, fixing multiple vulnerabilities including an unauthenticated API authentication bypass that is actively exploited, plus…

On 2026-09-16, Cisco published a batch of hardening advisories for Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), following a comprehensive internal security review that uncovered multiple vulnerabilities. Cisco grouped the issues by underlying vulnerability to help customers prioritize patching. The most urgent flaw is an unauthenticated remote authentication bypass via a crafted request to an ISE API endpoint, which grants unauthorized access to the web-based management interface and is known to be actively exploited (no CVE id for this flaw was provided in the reports). Other vulnerabilities include: authenticated remote code execution requiring valid administrative credentials, including command injection flaws that execute arbitrary commands as root; authenticated SQL and HQL injection in ISE/ISE-PIC APIs allowing arbitrary database queries and unauthorized viewing or modification of data; XML External Entity (XXE) injection; flaws allowing data access or manipulation, sensitive information disclosure, and a reload of certificate and key material; an unauthenticated remote RADIUS denial of service that could render ISE nodes unavailable; and unauthenticated local 802.1X session hijack (authentication bypass) and information disclosure. Cisco rated CVE-2026-20282 and CVE-2026-20283 (authenticated SQL injection and OS command execution) as High because attackers can easily reach root from the achieved privilege level; per the reports, a workaround addresses one of these two vulnerabilities, while Cisco states no workarounds are available for the remaining flaws, making software updates the only fix. In single-node deployments, the RADIUS DoS could prevent endpoints that have not yet authenticated from accessing the network until the node recovers.

  • Cisco released ISE and ISE-PIC hardening software updates on 2026-09-16 following a comprehensive internal security review; advisories are grouped by underlying vulnerability.
  • An unauthenticated remote authentication bypass via a crafted API request grants access to the ISE web-based management interface and is known to be actively exploited; no CVE id for this flaw appears in the reports.
  • CVE-2026-20282 and CVE-2026-20283 cover authenticated SQL injection and OS command execution and are rated High due to easy root escalation from the achieved privilege level.
  • Attack categories fixed: REST API authentication bypass, remote code execution, command injection as root (requires valid admin credentials), SQL and HQL injection via APIs, XXE injection, data access/manipulation with sensitive…
  • Exploitation requirements vary by flaw: unauthenticated remote (API bypass, RADIUS DoS), unauthenticated local (802.1X hijack, info disclosure), authenticated with valid admin credentials (RCE/command injection), and authenticated remote…
  • Workaround discrepancy across advisories: one workaround exists for one of CVE-2026-20282/CVE-2026-20283, but Cisco states no workarounds are available for the other vulnerabilities; software updates are the only fix.
  • The RADIUS DoS flaw (improper handling of crafted RADIUS requests) could render ISE nodes unavailable; in single-node deployments, unauthenticated endpoints could be locked out of network access until the node recovers.
  • ISE is widely deployed identity and network access control infrastructure, raising the deployment impact of these flaws.

Coverage timeline

  1. · 6h ago
    Cisco Security Advisories· 30
    Cisco Identity Services Engine Command Injection Vulnerabilities

    Authenticated attackers with admin credentials could exploit Cisco ISE command injection flaws to execute arbitrary commands as root; fixes released.

  2. · 6h ago
    Cisco Security Advisories· 58
    Cisco Identity Services Engine Hardening Release: September 2026

    Cisco ISE hardening release fixes multiple internally discovered vulnerabilities, including an authentication bypass known to be actively exploited.

  3. · 6h ago
    Cisco Security Advisories· 30
    Cisco Identity Services Engine SQL and HQL Injection Vulnerabilities

    Cisco fixed multiple authenticated SQL and HQL injection flaws in Identity Services Engine and ISE-PIC APIs allowing arbitrary database queries and unauthorized data access.

  4. · 6h ago
    Cisco Security Advisories· 30
    Cisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilities

    Cisco patched Identity Services Engine flaws letting unauthenticated local attackers bypass 802.1X authentication or disclose sensitive information.

  5. · 6h ago
    Cisco Security Advisories· 25
    Cisco Identity Services Engine Information Disclosure Vulnerability

    Cisco patched an ISE API flaw letting an authenticated administrator view sensitive data including hashed credentials via crafted API requests.

  6. · 6h ago
    Cisco Security Advisories· 38
    Cisco Identity Services Engine Authentication Bypass Vulnerabilities

    Cisco fixed multiple authentication bypass flaws in Identity Services Engine and ISE-PIC enabling remote data access, manipulation, and certificate material disruption.

  7. · 6h ago
    Cisco Security Advisories· 35
    Cisco Identity Services Engine RADIUS Denial of Service Vulnerability

    Cisco patched a RADIUS flaw in Identity Services Engine letting unauthenticated remote attackers trigger denial of service on ISE nodes.

  8. · 6h ago
    Cisco Security Advisories· 30
    Cisco Identity Services Engine Multiple Path Traversal Vulnerabilities

    Cisco ISE and ISE-PIC contain multiple path traversal vulnerabilities allowing remote attacks; fixes released with no workarounds available.

  9. · 6h ago
    Cisco Security Advisories· 55
    Cisco Identity Services Engine Authentication Bypass Vulnerability

    Cisco patched an unauthenticated API authentication bypass in Identity Services Engine allowing attackers to access the web-based management interface.

  10. · 6h ago
    Cisco Security Advisories· 26
    Cisco Identity Services Engine Authorization Bypass Vulnerabilities

    Cisco fixed authorization bypass flaws in ISE and ISE-PIC web management letting authenticated admins modify file descriptions via crafted HTTP requests.

  11. · 6h ago
    Cisco Security Advisories· 25
    Cisco Identity Services Engine Cross-Site Scripting Vulnerability

    Cisco patched a reflected XSS in the ISE management interface allowing unauthenticated attackers to execute script via crafted links.

  12. · 6h ago
    Cisco Security Advisories· 40
    Cisco Identity Services Engine Remote Code Execution Vulnerabilities

    Cisco patched multiple authenticated remote code execution vulnerabilities in Identity Services Engine that require valid administrative credentials.

  13. · 6h ago
    Cisco Security Advisories· 45
    Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities

    Cisco fixed ISE vulnerabilities enabling authenticated SQL injection and OS command execution; CVE-2026-20282 and CVE-2026-20283 rated High.

  14. · 6h ago
    Cisco Security Advisories· 48
    Cisco Identity Services Engine Vulnerabilities

    Cisco patched ISE and ISE-PIC flaws enabling REST API authentication bypass, remote code execution, SQL injection, and XXE attacks.

  15. · 6h ago
    Cisco Security Advisories· 28
    Cisco Identity Services Engine SQL Injection Vulnerabilities

    Cisco released fixes for multiple SQL injection vulnerabilities in Identity Services Engine as part of its September 2026 advisory batch.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20282
Authenticated OS Write-Access Flaw in Cisco Identity Services Engine

CVE-2026-20282 is a vulnerability in Cisco Identity Services Engine (ISE) caused by insufficient validation of user-supplied input. An attacker who already has valid administrative credentials can send a crafted HTTP request to an affected device and obtain write access to the underlying operating system. Cisco rated the flaw High despite the Medium CVSS score because an attacker can easily escalate from the achieved privilege level to root, effectively yielding full control of the appliance. Any organization running Cisco ISE is affected, though exploitation requires both network reachability to the device and stolen or malicious administrator credentials. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known.

Do: Review Cisco's advisory for CVE-2026-20282 and upgrade ISE to the fixed release it specifies, prioritizing the fix since Cisco rates the impact High due to the easy path to root. Restrict ISE administration interfaces to dedicated management networks and enforce strong credential hygiene/MFA for ISE admin accounts, since valid admin credentials are required for exploitation. Check ISE admin and audit logs for unexpected administrative sessions or unusual HTTP requests to management endpoints.

4.9
  • Cisco Identity Services Engine (ISE)
large≈10,000–100,000 enterprise ISE deployments/nodes worldwide (estimate), though only a small fraction have admin interfaces reachable by potential attackers
CVE-2026-20283
Authenticated OS command injection (RCE) in Cisco ISE IPsec Open API

Cisco Identity Services Engine (ISE) contains an operating system command injection flaw (CWE-78) in its IPsec Open API endpoint, caused by insufficient validation of user-supplied input in IPsec Open API calls. An authenticated, remote attacker who holds valid administrative credentials can send crafted input to the endpoint to execute arbitrary commands on the underlying operating system. Exploitation additionally requires the ISE node to have more than one network interface, one of which is configured as an active IPsec tunnel. Although the CVSS 3.1 base score is 6.5 (Medium), Cisco assigned a Security Impact Rating of High because it is easy to escalate from the achieved privilege level to root. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not listed in CISA's KEV catalog.

Do: Upgrade ISE to the fixed release identified in Cisco's advisory; the related-headline bundle indicates companion ISE RCE/API vulnerabilities fixed at the same time, so apply the full set of patches. Until patching, restrict access to the Open API to trusted management networks, disable the Open API or IPsec tunnel configuration where unused, and limit and rotate administrative credentials. Audit ISE deployments for multi-interface nodes with active IPsec tunnels, as those are the exploitable targets.

6.5
  • Cisco Identity Services Engine (ISE)
moderatelikely on the order of thousands of ISE deployments meet the preconditions, out of an ISE installed base plausibly in the tens of thousands