CVE-2025-20281Active Exploitation(cisco / identity_services_engine)

LOWCVSS 10.0 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for cisco identity_services_engine systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-08-18. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_services_engine
  • identity_services_engine_passive_identity_connector

Threat summary

  • Active exploitation appears in 3 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 2 mentions (2026-03-09); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
identity_services_engineidentity_services_engine_passive_identity_connector

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-09: 2Mentions · 2026-03-10: 1Active Exploitation · 2026-03-09: 2Active Exploitation · 2026-03-10: 1Technical Details · 2026-03-09: 203-0903-10
Signal classification1 categories
Active Exploitation
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-092
Active Exploitation2
2026-03-101
Active Exploitation1
Full discourse3 posts
  • CrowdSec@Crowd_Security
    Active Exploitation

    🚨 In this week’s newsletter, we dive into CVE-2025-20281, a critical Cisco Identity Services Engine (ISE) RCE vulnerability, as CrowdSec Threat Intelligence observes a new wave of exploitation attempts. We break down how the vulnerability works, why attackers are now incorporating it into opportunistic exploit kits, and what defenders should do to stay protected. Read the full analysis and protect your systems 👉 https://www.crowdsec.net/vulntracking-report/cve-2025-20281-cisco-ise-rce-exploitation

    Post summary

    The tweet highlights that CrowdSec has observed a new wave of exploitation attempts for the critical Cisco ISE RCE vulnerability, emphasizing ongoing active exploitation.

    00010249
    19.5K followersView on X
  • Prevention Internet ®@Prevention_web
    Active Exploitation

    CVE-2025-20281, une nouvelle vague d'exploitation active de Cisco Identity Services Engine https://ift.tt/UMfI2gD #PreventionInternet #Cybersécurité

    Post summary

    The tweet announces a new wave of active exploitation against Cisco Identity Services Engine involving CVE-2025-20281.

    00000105
    473 followersView on X
  • FarVision Networks@FarVisionNetwks
    Active Exploitation

    https://zurl.co/WTy7f CVE-2025-20281: Critical Cisco ISE RCE Vulnerability Sees New Exploitation Wave https://t.co/w0SiggbXdm

    Post summary

    The post announces that CVE-2025-20281, a critical RCE flaw in Cisco ISE, is currently being actively exploited, though it offers no PoC or exploit code details.

    0000078
    438 followersView on X
CPE platform detail18 entries

18 of 18 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--

Explore more