Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2834 articles · 164365 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-20190EXPLOITED
Cisco · Cisco Identity Services Engine Software

Cisco Identity Services Engine Information Disclosure Vulnerability

Description

A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.

Affected Products

VendorProductVersions
CiscoCisco Identity Services Engine Software3.4.0, 3.4 Patch 1, 3.4 Patch 2, 3.4 Patch 3, 3.5.0, 3.4 Patch 4, 3.5 Patch 1, 3.4 Patch 5, 3.5 Patch 2, 3.4.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciscisco ise passive identity connectormitre_affected90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv

Related News (2 articles)

Tier C
VulDB5h ago
CVE-2026-20190 | Cisco Identity Services Engine Software 3.4.0/3.5.0 Traffic improper authorization (cisco-sa-ise-multi-G5WP8vv)
→ No new info (linked only)
Tier A
Cisco Security6h ago
Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-285
PublishedJun 17, 2026
Last enriched5h agov3
Tags
CVE-2026-20190
Trending Score66
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-20181EXP
Cisco Identity Services Engine Remote Code Execution Vulnerability
Trending: 65
MEDIUMCVE-2026-20220
Cisco Crosswork Network Controller Remote Code Execution Vulnerability
Trending: 34
CRITICALPRE-CVE
Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities
Trending: 30
MEDIUMCVE-2026-20171
Cisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service Vulnerability
Trending: 2
MEDIUMCVE-2026-20206
Cisco ThousandEyes BrowserBot Command Injection Vulnerability
Trending: 2

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 17, 2026
Discovered by ZDM
Jun 17, 2026
Updated: description, severity, exploitAvailable, activelyExploited
Jun 17, 2026
Updated: tags
Jun 17, 2026
Actively Exploited
Jun 17, 2026
Exploit Available
Jun 17, 2026

Version History

v3
Last enriched 5h ago
v3Tier C5h ago

Updated description with new details, changed severity to CRITICAL, and added CVE-2026-20190 as a tag.

tags
via VulDB
v2Tier A6h ago

Updated description to include multiple vulnerabilities and changed severity to CRITICAL, indicating that exploits are now available and actively exploited.

descriptionseverityexploitAvailableactivelyExploited
via Cisco Security
v16h ago

Initial creation