cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
117
Views
2
Helpful
1
Replies

Cisco Identity Services Engine Remote Code Execution Vulnerabilities

Singhaam
Spotlight
Spotlight

Cisco has released a security Update containing security patches for multiple vulnerabilities. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and security restriction bypass on the targeted system.
Some security vulnerabilities are mentioned below:
CVE-2026-76423 (10): A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks.
CVE-2026-76460 (10): This vulnerability is being exploited in the wild. A flaw in API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint.
CVE-2026-20307 (9.9): A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials.
CVE-2026-20295 (8.6): A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to exhaust the available memory of an affected device.

1 Reply 1