Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2834 articles · 164367 vulns · 36/41 feeds (7d)
← Back to list
9.1
CVE-2026-20181EXPLOITEDPATCHED
Cisco · Cisco Identity Services Engine Software

Cisco Identity Services Engine Remote Code Execution Vulnerability

Description

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

Affected Products

VendorProductVersions
CiscoCisco Identity Services Engine Software3.1.0, 3.1.0 p1, 3.1.0 p3, 3.1.0 p2, 3.2.0, 3.1.0 p4, 3.1.0 p5, 3.2.0 p1, 3.1.0 p6, 3.2.0 p2, 3.1.0 p7, 3.3.0, 3.2.0 p3, 3.2.0 p4, 3.1.0 p8, 3.2.0 p5, 3.2.0 p6, 3.1.0 p9, 3.3 Patch 2, 3.3 Patch 1, 3.3 Patch 3, 3.4.0, 3.2.0 p7, 3.3 Patch 4, 3.4 Patch 1, 3.1.0 p10, 3.3 Patch 5, 3.3 Patch 6, 3.4 Patch 2, 3.3 Patch 7, 3.4 Patch 3, 3.5.0, 3.4 Patch 4, 3.3 Patch 8, 3.2 Patch 8, 3.5 Patch 1, 3.3 Patch 9, 3.2 Patch 9, 3.4 Patch 5, 3.5 Patch 3, 3.5 Patch 2, 3.3 Patch 10, 3.2 Patch 10, 3.1.0 p11, 3.2.0, 3.1.0, 3.3.0, 3.4.0, 3.5.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciscisco ise passive identity connectormitre_affected90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv

Related News (2 articles)

Tier C
VulDB5h ago
CVE-2026-20181 | Cisco Identity Services Engine Software up to 3.5.0 HTTP path traversal (cisco-sa-ise-multi-G5WP8vv)
→ No new info (linked only)
Tier A
Cisco Security6h ago
Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
3.5.0
CWECWE-22
PublishedJun 17, 2026
Last enriched5h agov3
Trending Score65
Source articles2
Independent2
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20190EXP
Cisco Identity Services Engine Information Disclosure Vulnerability
Trending: 66
MEDIUMCVE-2026-20220
Cisco Crosswork Network Controller Remote Code Execution Vulnerability
Trending: 34
CRITICALPRE-CVE
Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities
Trending: 30
MEDIUMCVE-2026-20171
Cisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service Vulnerability
Trending: 2
MEDIUMCVE-2026-20206
Cisco ThousandEyes BrowserBot Command Injection Vulnerability
Trending: 2

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 17, 2026
Discovered by ZDM
Jun 17, 2026
Updated: exploitAvailable, activelyExploited
Jun 17, 2026
Updated: patchAvailable
Jun 17, 2026
Actively Exploited
Jun 17, 2026
Exploit Available
Jun 17, 2026
Patch Available
Jun 17, 2026

Version History

v3
Last enriched 5h ago
v3Tier C5h ago

Updated description with new details about the vulnerability and added patch information for version 3.5.0.

patchAvailable
via VulDB
v2Tier A6h ago

Updated exploit availability to true and marked the vulnerability as actively exploited.

exploitAvailableactivelyExploited
via Cisco Security
v16h ago

Initial creation