Cisco fixes critical command execution in Identity Services Engine
Cisco has published fixes for Identity Services Engine (ISE) and ISE Passive Identity Connector. CVE-2026-20181 is a critical authenticated remote command-execution issue; exploitation requires valid administrative credentials and can provide user-level OS access followed by escalation to root. CVE-2026-20190 is a high-severity information-disclosure issue that can allow unauthenticated access to sensitive data, including hashed credentials. Cisco reports no known exploitation and no workaround. Fixed releases include ISE and ISE-PIC 3.3 Patch 11 and 3.4 Patch 6, with hotfix coverage for 3.5 and inclusion in 3.5 Patch 4.
What this means for your organisation
ISE is the hub deciding who gets onto the network. An attacker with root on that server can effectively write their own access rules for the whole infrastructure, and leaked password hashes feed onward attacks against other systems. The relationship between the two flaws is worth noting: one leaks credential material, the other needs administrative credentials. Together they form a coherent attack chain.
Berigo recommends
- Upgrade to ISE and ISE-PIC 3.3 Patch 11, 3.4 Patch 6 or the corresponding 3.5 hotfix.
- Rotate ISE administrator credentials after upgrading, since hashes may have been exposed.
- Restrict the ISE management interface to a dedicated operations network with multi-factor authentication.
- Review changes to access policies and administrator accounts on ISE for the period before the update.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch