Cisco September 2026 ISE Hardening Release Patches Actively Exploited Authentication Bypass and Multiple RCE, Injection, and DoS Flaws
Cisco released hardening software updates for Identity Services Engine (ISE) and ISE-PIC on 2026-09-16 after an internal security review, fixing multiple vulnerabilities including an unauthenticated API authentication bypass that is actively exploited, plus…
On 2026-09-16, Cisco published a batch of hardening advisories for Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), following a comprehensive internal security review that uncovered multiple vulnerabilities. Cisco grouped the issues by underlying vulnerability to help customers prioritize patching. The most urgent flaw is an unauthenticated remote authentication bypass via a crafted request to an ISE API endpoint, which grants unauthorized access to the web-based management interface and is known to be actively exploited (no CVE id for this flaw was provided in the reports). Other vulnerabilities include: authenticated remote code execution requiring valid administrative credentials, including command injection flaws that execute arbitrary commands as root; authenticated SQL and HQL injection in ISE/ISE-PIC APIs allowing arbitrary database queries and unauthorized viewing or modification of data; XML External Entity (XXE) injection; flaws allowing data access or manipulation, sensitive information disclosure, and a reload of certificate and key material; an unauthenticated remote RADIUS denial of service that could render ISE nodes unavailable; and unauthenticated local 802.1X session hijack (authentication bypass) and information disclosure. Cisco rated CVE-2026-20282 and CVE-2026-20283 (authenticated SQL injection and OS command execution) as High because attackers can easily reach root from the achieved privilege level; per the reports, a workaround addresses one of these two vulnerabilities, while Cisco states no workarounds are available for the remaining flaws, making software updates the only fix. In single-node deployments, the RADIUS DoS could prevent endpoints that have not yet authenticated from accessing the network until the node recovers.
- Cisco released ISE and ISE-PIC hardening software updates on 2026-09-16 following a comprehensive internal security review; advisories are grouped by underlying vulnerability.
- An unauthenticated remote authentication bypass via a crafted API request grants access to the ISE web-based management interface and is known to be actively exploited; no CVE id for this flaw appears in the reports.
- CVE-2026-20282 and CVE-2026-20283 cover authenticated SQL injection and OS command execution and are rated High due to easy root escalation from the achieved privilege level.
- Attack categories fixed: REST API authentication bypass, remote code execution, command injection as root (requires valid admin credentials), SQL and HQL injection via APIs, XXE injection, data access/manipulation with sensitive…
- Exploitation requirements vary by flaw: unauthenticated remote (API bypass, RADIUS DoS), unauthenticated local (802.1X hijack, info disclosure), authenticated with valid admin credentials (RCE/command injection), and authenticated remote…
- Workaround discrepancy across advisories: one workaround exists for one of CVE-2026-20282/CVE-2026-20283, but Cisco states no workarounds are available for the other vulnerabilities; software updates are the only fix.
- The RADIUS DoS flaw (improper handling of crafted RADIUS requests) could render ISE nodes unavailable; in single-node deployments, unauthenticated endpoints could be locked out of network access until the node recovers.
- ISE is widely deployed identity and network access control infrastructure, raising the deployment impact of these flaws.
Coverage timelineoldest first · each row is one article
- · 6h agoCisco Identity Services Engine Command Injection Vulnerabilities
Cisco Security Advisories· 30
Authenticated attackers with admin credentials could exploit Cisco ISE command injection flaws to execute arbitrary commands as root; fixes released.
- · 6h agoCisco Identity Services Engine Hardening Release: September 2026
Cisco Security Advisories· 58
Cisco ISE hardening release fixes multiple internally discovered vulnerabilities, including an authentication bypass known to be actively exploited.
- · 6h agoCisco Identity Services Engine SQL and HQL Injection Vulnerabilities
Cisco Security Advisories· 30
Cisco fixed multiple authenticated SQL and HQL injection flaws in Identity Services Engine and ISE-PIC APIs allowing arbitrary database queries and unauthorized data access.
- · 6h agoCisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilities
Cisco Security Advisories· 30
Cisco patched Identity Services Engine flaws letting unauthenticated local attackers bypass 802.1X authentication or disclose sensitive information.
- · 6h agoCisco Identity Services Engine Information Disclosure Vulnerability
Cisco Security Advisories· 25
Cisco patched an ISE API flaw letting an authenticated administrator view sensitive data including hashed credentials via crafted API requests.
- · 6h agoCisco Identity Services Engine Authentication Bypass Vulnerabilities
Cisco Security Advisories· 38
Cisco fixed multiple authentication bypass flaws in Identity Services Engine and ISE-PIC enabling remote data access, manipulation, and certificate material disruption.
- · 6h agoCisco Identity Services Engine RADIUS Denial of Service Vulnerability
Cisco Security Advisories· 35
Cisco patched a RADIUS flaw in Identity Services Engine letting unauthenticated remote attackers trigger denial of service on ISE nodes.
- · 6h agoCisco Identity Services Engine Multiple Path Traversal Vulnerabilities
Cisco Security Advisories· 30
Cisco ISE and ISE-PIC contain multiple path traversal vulnerabilities allowing remote attacks; fixes released with no workarounds available.
- · 6h agoCisco Identity Services Engine Authentication Bypass Vulnerability
Cisco Security Advisories· 55
Cisco patched an unauthenticated API authentication bypass in Identity Services Engine allowing attackers to access the web-based management interface.
- · 6h agoCisco Identity Services Engine Authorization Bypass Vulnerabilities
Cisco Security Advisories· 26
Cisco fixed authorization bypass flaws in ISE and ISE-PIC web management letting authenticated admins modify file descriptions via crafted HTTP requests.
- · 6h agoCisco Identity Services Engine Cross-Site Scripting Vulnerability
Cisco Security Advisories· 25
Cisco patched a reflected XSS in the ISE management interface allowing unauthenticated attackers to execute script via crafted links.
- · 6h agoCisco Identity Services Engine Remote Code Execution Vulnerabilities
Cisco Security Advisories· 40
Cisco patched multiple authenticated remote code execution vulnerabilities in Identity Services Engine that require valid administrative credentials.
- · 6h agoCisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities
Cisco Security Advisories· 45
Cisco fixed ISE vulnerabilities enabling authenticated SQL injection and OS command execution; CVE-2026-20282 and CVE-2026-20283 rated High.
- · 6h agoCisco Identity Services Engine Vulnerabilities
Cisco Security Advisories· 48
Cisco patched ISE and ISE-PIC flaws enabling REST API authentication bypass, remote code execution, SQL injection, and XXE attacks.
- · 6h agoCisco Identity Services Engine SQL Injection Vulnerabilities
Cisco Security Advisories· 28
Cisco released fixes for multiple SQL injection vulnerabilities in Identity Services Engine as part of its September 2026 advisory batch.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20282 | Authenticated OS Write-Access Flaw in Cisco Identity Services Engine CVE-2026-20282 is a vulnerability in Cisco Identity Services Engine (ISE) caused by insufficient validation of user-supplied input. An attacker who already has valid administrative credentials can send a crafted HTTP request to an affected device and obtain write access to the underlying operating system. Cisco rated the flaw High despite the Medium CVSS score because an attacker can easily escalate from the achieved privilege level to root, effectively yielding full control of the appliance. Any organization running Cisco ISE is affected, though exploitation requires both network reachability to the device and stolen or malicious administrator credentials. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known. Do: Review Cisco's advisory for CVE-2026-20282 and upgrade ISE to the fixed release it specifies, prioritizing the fix since Cisco rates the impact High due to the easy path to root. Restrict ISE administration interfaces to dedicated management networks and enforce strong credential hygiene/MFA for ISE admin accounts, since valid admin credentials are required for exploitation. Check ISE admin and audit logs for unexpected administrative sessions or unusual HTTP requests to management endpoints. | 4.9 | — |
| large≈10,000–100,000 enterprise ISE deployments/nodes worldwide (estimate), though only a small fraction have admin interfaces reachable by potential attackers | ||
| CVE-2026-20283 | Authenticated OS command injection (RCE) in Cisco ISE IPsec Open API Cisco Identity Services Engine (ISE) contains an operating system command injection flaw (CWE-78) in its IPsec Open API endpoint, caused by insufficient validation of user-supplied input in IPsec Open API calls. An authenticated, remote attacker who holds valid administrative credentials can send crafted input to the endpoint to execute arbitrary commands on the underlying operating system. Exploitation additionally requires the ISE node to have more than one network interface, one of which is configured as an active IPsec tunnel. Although the CVSS 3.1 base score is 6.5 (Medium), Cisco assigned a Security Impact Rating of High because it is easy to escalate from the achieved privilege level to root. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not listed in CISA's KEV catalog. Do: Upgrade ISE to the fixed release identified in Cisco's advisory; the related-headline bundle indicates companion ISE RCE/API vulnerabilities fixed at the same time, so apply the full set of patches. Until patching, restrict access to the Open API to trusted management networks, disable the Open API or IPsec tunnel configuration where unused, and limit and rotate administrative credentials. Audit ISE deployments for multi-interface nodes with active IPsec tunnels, as those are the exploitable targets. | 6.5 | — |
| moderatelikely on the order of thousands of ISE deployments meet the preconditions, out of an ISE installed base plausibly in the tens of thousands |