[CIVN-2026-0462] Multiple Vulnerabilities in Cisco Identity Services Engine

By Published On: September 18, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Cisco Identity Services Engine


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Systems Affected


Cisco Identity Services Engine (ISE)

Cisco ISE Passive Identity Connector (ISE-PIC)

Overview


Multiple vulnerabilities have been reported across various components of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) which could allow remote attackers to bypass authentication entirely, execute arbitrary code or commands as the root user, conduct SQL injection attacks, perform XML External Entity (XXE) injections, and gain full write access to the underlying operating system.


Risk Assessment:

High risk of data manipulation and service disruption.


Impact Assessment:

Potential impact on confidentiality, integrity, and availability of the system.


Target Audience:

All IT administrators and individuals responsible for maintaining and updating this software.


Description


1. Authentication Bypass Vulnerability ( CVE-2026-76460   )


This vulnerability exists due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint.

Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.


2. Command Injection Vulnerability ( CVE-2026-20305   CVE-2026-20306   )


These vulnerabilities exist due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of an affected device.

Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code on the device and elevate privileges to root.


3. SQL Injection Vulnerability ( CVE-2026-20284   )


This vulnerability exists due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device.

Successful exploitation of this vulnerability could allow the attacker to view or modify data on the underlying database for the affected device.


4. Command  Injection Vulnerability ( CVE-2026-20283   )


This vulnerability exists due to insufficient validation of user-supplied input in IPsec Open API calls. An attacker could exploit this vulnerability by sending a crafted input to the IPsec Open API endpoint on an affected device.

Successful exploitation of this vulnerability could allow the attacker to execute arbitrary commands on the underlying operating system.


5. Authenticated Write Vulnerability ( CVE-2026-20282   )


This vulnerability exists due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by a crafted HTTP request to an affected device.

Successful exploitation of this vulnerability could allow the attacker to obtain write access to the underlying operating system.


6. Remote Code Execution Vulnerability ( CVE-2026-76176   CVE-2026-20211   CVE-2026-20307   )


These vulnerabilities exist due to insecure deserialization of a user-supplied Java byte stream or insufficient validation of user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted serialized Java object to the web-based management interface of an affected device and HTTP request to an affected device.

Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code on the device, obtain system-level access to the underlying operating system, user-level access to the underlying operating system and elevate privileges to root


Solution


Apply appropriate updates as mentioned in Cisco Advisory

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5


https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-e2CuZCYZ


https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc


https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57



Vendor Information


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-e2CuZCYZ

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57


References


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-e2CuZCYZ

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57


CVE Name

CVE-2026-76460

CVE-2026-20305

CVE-2026-20306

CVE-2026-20284

CVE-2026-20283

CVE-2026-20282

CVE-2026-76176

CVE-2026-20211

CVE-2026-20307




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqtQCYACgkQ3jCgcSdc

ys9ChQ//W3GTtLEj6mlqyBZ91oB0LeCUKksfRl5w2YrKUgmfLG2dhrelJywFS1NH

xHzJNFmGyDgU5t97L9Gev6GHZtAVrdhv9kajUH1YC+XOZhedNzWsrhFcVSpvQCbf

YO7pDjjpJ32c2fg4JC2OAB0AcxOzb8A+he1QmHaGgO8Kq6qlWyvHNILq9FvsUlAP

j4jOI9q6yapXKhuN/Dl/1V7NW8dEx3yDPCB4IzZyPWGRrc7/3kFfpmRS1t+NzKCA

/Q9+pTe3NUM8DxGymSKn8/AqHpqJ/z1Vkmem6pmAFa9qH8e6OeGxTkn1PxGPXR4q

R+7/Gh5L6zkuXnQ5EPEZb/VxEhbPzeACm9ccBtjSHjOfgqAPH1zsvhxxJ6p+k9+b

28d8Jwa+Ptra/8ijVNvnzazZ/CvXnSkpSOMj/XYLVhITgvAI4Zxl7v8KA4nWaDyh

BjVHYOm6FV4HRxdlS2jDw2wxTYhdjEE1C790lMPH8/avRi/gAZ0foh9cJvFy/FiG

3XLgX1LvYOsPqH2hsty7X3gFcKNs4giYzPtuEjhkyYxZWPELvF/2X2Y2Nxo5irxM

KXOsRK8fPWCo1NDcdx6LuEB8G+GOZRO+7yctZnpSFkSKw9jalUseJO2hPJFX2/G3

oY/GWADN2XQ4Z1pDO5TWzfcOMk66WRKMk1PQFUw0HCUJWCiWgjs=

=jSDC

—–END PGP SIGNATURE—–

Share this article