Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2402 articles · 111888 vulns · 38/41 feeds (7d)
← Back to list
9.9
CVE-2026-20147EXPLOITED
cis · ise

Cisco Identity Services Engine Remote Code Execution Vulnerability

Description

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node ISE deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

Affected Products

VendorProductVersions
cisise3.1.0, 3.1.0 p1, 3.1.0 p3, 3.1.0 p2, 3.2.0, 3.1.0 p4, 3.1.0 p5, 3.2.0 p1, 3.1.0 p6, 3.2.0 p2, 3.1.0 p7, 3.3.0, 3.2.0 p3, 3.2.0 p4, 3.1.0 p8, 3.2.0 p5, 3.2.0 p6, 3.1.0 p9, 3.3 Patch 2, 3.3 Patch 1, 3.3 Patch 3, 3.4.0, 3.2.0 p7, 3.3 Patch 4, 3.4 Patch 1, 3.1.0 p10, 3.3 Patch 5, 3.3 Patch 6, 3.4 Patch 2, 3.3 Patch 7, 3.4 Patch 3, 3.5.0, 3.4 Patch 4, 3.3 Patch 8, 3.2 Patch 8, 3.5 Patch 1, 3.3 Patch 9, 3.2 Patch 9, 3.4 Patch 5, 3.5 Patch 2, 3.2.0, 3.1.0, 3.3.0, 3.4.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciscisco identity services engine (ise)cert_advisory90%
ciscisco ise passive identity connectormitre_affected90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ

Related News (9 articles)

Tier D
The Hacker News3h ago
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
→ No new info (linked only)
Tier B
CERT-FR16h ago
Bulletin d'actualité CERTFR-2026-ACT-018 (20 avril 2026)
→ No new info (linked only)
Tier D
BleepingComputer4d ago
Cisco says critical Webex Services flaw requires customer action
→ No new info (linked only)
Tier B
BSI Advisories4d ago
[NEU] [hoch] Cisco Identity Services Engine (ISE): Mehrere Schwachstellen
→ No new info (linked only)
Tier D
SecurityWeek4d ago
Cisco Patches Critical Vulnerabilities in Webex, ISE
→ No new info (linked only)
Tier D
Heise Security4d ago
Cisco: Kritische Codeschmuggel-Lücken in ISE und mehr geschlossen
→ No new info (linked only)
Tier B
CERT-FR4d ago
Multiples vulnérabilités dans les produits Cisco (16 avril 2026)
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-20147 | Cisco Identity Services Engine Software command injection (cisco-sa-ise-rce-traversal-8bYndVrZ)
→ No new info (linked only)
Tier A
Cisco Security5d ago
Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities
→ No new info (linked only)
CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-77
PublishedApr 15, 2026
Last enriched4d agov3
Trending Score87
Source articles9
Independent8
Info Completeness9/14
Missing: epss, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-20184
Cisco Webex Meetings Certificate Validation Vulnerability
Trending: 81
CRITICALCVE-2026-20180
Cisco Identity Services Engine Multiple Remote Code Execution Vulnerability
Trending: 64
CRITICALCVE-2026-20186
Cisco Identity Services Engine Multiple Authenticated Remote Code Execution Vulnerability
Trending: 64
MEDIUMCVE-2026-20148EXP
Cisco Identity Services Engine Path Traversal Vulnerability
Trending: 35
MEDIUMCVE-2026-20132EXP
Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities
Trending: 33

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 15, 2026
Discovered by ZDM
Apr 15, 2026
Updated: description, exploitAvailable, activelyExploited
Apr 15, 2026
Updated: cweIds
Apr 15, 2026
Actively Exploited
Apr 16, 2026
Exploit Available
Apr 16, 2026

Version History

v3
Last enriched 4d ago
v3Tier C4d ago

Updated description with new details and added CWE-94.

cweIds
via VulDB
v2Tier A5d ago

Updated description with details on multiple vulnerabilities and marked exploit availability and active exploitation status as true.

descriptionexploitAvailableactivelyExploited
via Cisco Security
v15d ago

Initial creation