ZDI publishes three Cisco Identity Services Engine advisories: two authenticated RCE flaws and one XXE information disclosure
On 2026-09-18, the Zero Day Initiative published advisories ZDI-26-716, ZDI-26-717, and ZDI-26-718 for Cisco Identity Services Engine, disclosing CVE-2026-20176 (createDBLink command injection RCE, CVSS 7.2), CVE-2026-20211 (AlarmMessageDiskQueue…
The Zero Day Initiative published three advisories for Cisco Identity Services Engine on 2026-09-18. ZDI-26-716 describes a command injection vulnerability in the createDBLink function that allows authenticated remote attackers to execute arbitrary code, tracked as CVE-2026-20176 with a CVSS rating of 7.2; the advisory reports no exploitation in the wild. ZDI-26-717 describes a deserialization of untrusted data vulnerability in AlarmMessageDiskQueue enabling authenticated remote code execution, tracked as CVE-2026-20211 with a CVSS score of 7.2. ZDI-26-718 describes an XML external entity (XXE) processing vulnerability in MnTRESTLivelogService that allows remote, authenticated attackers to disclose sensitive information, tracked as CVE-2026-20235 with a CVSS score of 4.9. All three flaws require valid credentials to exploit. The reports do not list affected versions or patch information.
- ZDI advisory ZDI-26-716 (published 2026-09-18): command injection in the createDBLink function of Cisco Identity Services Engine enables authenticated remote code execution; tracked as CVE-2026-20176, CVSS 7.2; no exploitation in the wild…
- ZDI advisory ZDI-26-717 (published 2026-09-18): deserialization of untrusted data in Cisco ISE's AlarmMessageDiskQueue enables authenticated remote code execution; tracked as CVE-2026-20211, CVSS 7.2.
- ZDI advisory ZDI-26-718 (published 2026-09-18): XXE in Cisco ISE's MnTRESTLivelogService enables authenticated remote information disclosure; tracked as CVE-2026-20235, CVSS 4.9.
- All three vulnerabilities require valid credentials (authentication) to exploit.
- Aggregate impact: two authenticated remote code execution flaws (CVSS 7.2 each) and one authenticated information disclosure flaw (CVSS 4.9).
- The reports do not specify affected ISE versions or patch/fix availability.
Coverage timelineoldest first · each row is one article
- · 12h agoZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability
ZDI Published Advisories· 20
ZDI detailed CVE-2026-20235, an authenticated XML external entity information disclosure flaw (CVSS 4.9) in Cisco Identity Services Engine.
- · 12h agoZDI-26-717: Cisco Identity Services Engine AlarmMessageDiskQueue Deserialization of Untrusted Data Remote Code Execution Vulnerability
ZDI Published Advisories· 25
ZDI disclosed CVE-2026-20211, an authenticated deserialization flaw (CVSS 7.2) enabling remote code execution in Cisco Identity Services Engine.
- · 12h agoZDI-26-716: Cisco Identity Services Engine createDBLink Command Injection Remote Code Execution Vulnerability
ZDI Published Advisories· 48
ZDI disclosed CVE-2026-20176, an authenticated command injection flaw enabling remote code execution in Cisco Identity Services Engine, rated CVSS 7.2.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20176 +1 in the same advisory: …20211 | Authenticated Command Injection in Cisco Identity Services Engine (ISE) Cisco ISE contains a command injection flaw (CWE-77) caused by insufficient validation of user-supplied input. An authenticated, remote attacker who already holds valid high-privileged administrative credentials can send a crafted HTTP request to an affected device to run arbitrary commands on the underlying operating system, gaining system-level access and then elevating to root. In single-node deployments, successful exploitation can render the ISE node unavailable, causing a denial of service in which endpoints that have not yet authenticated cannot access the network until the node is restored. All Cisco ISE deployments are potentially affected, though exploitation requires stolen or compromised administrator credentials rather than anonymous access. No public proof-of-concept is known and the flaw is not listed in CISA's KEV, so exploitation has not been confirmed. Do: Upgrade to the fixed release specified in Cisco's PSIRT advisory for CVE-2026-20176 (not listed in this data). Until patched, restrict access to the ISE administration interface to trusted management networks, audit high-privileged admin accounts for compromise (since valid admin credentials are required), and monitor for unexpected root-level or shell activity on ISE appliances. Operators of single-node deployments should prepare failover/restore plans, as exploitation would block new endpoint network authentication until the node is recovered. | 9.1 | — |
| largelikely tens of thousands of enterprise ISE deployments/nodes worldwide (estimated) | ||
| CVE-2026-20235 | Authenticated XXE Information Disclosure in Cisco Identity Services Engine (ISE) API CVE-2026-20235 is an information-disclosure flaw in the API of Cisco Identity Services Engine (ISE), caused by insufficient validation of user-supplied parameters in API requests (CWE-89); ZDI tracks it as XML External Entity processing in the MnT REST LiveLog service. An authenticated, remote attacker who already holds valid administrative credentials can trigger it by sending a crafted API request to an affected device. A successful exploit leaks sensitive information, including hashed credentials that could be cracked or reused in follow-on attacks. Any organization running Cisco ISE that exposes the affected API to administrators is in scope; exploitation requires high privileges (PR:H), which limits practical impact. The flaw is rated 4.9 (medium), is not in CISA KEV, has no known public proof-of-concept, and there are no reports of exploitation in the wild. Do: Upgrade Cisco ISE to the fixed release listed in the Cisco PSIRT advisory for CVE-2026-20235 (fixed versions not provided in this data). As an interim mitigation, restrict access to the ISE administration portal and the MnT REST API to trusted management networks and least-privilege administrator accounts. Because hashed credentials can be harvested, review ISE API logs for unexpected or anomalous requests and rotate/monitor administrative and internal user credentials. | 4.9 | — |
| large≈20,000–50,000 enterprise/government ISE deployments worldwide (est.) |