CVE-2025-20337Active Exploitation(cisco / identity_services_engine)

MEDIUMCVSS 10.0 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch cisco identity_services_engine systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-08-18. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-74

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_services_engine
  • identity_services_engine_passive_identity_connector

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked at 2 mentions on most recent observed day (2026-07-16)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
identity_services_engineidentity_services_engine_passive_identity_connector

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-14: 1Mentions · 2026-07-16: 2Active Exploitation · 2026-07-16: 2Patch / Workaround · 2026-02-14: 1Patch / Workaround · 2026-07-16: 1Technical Details · 2026-07-16: 202-1407-16
Signal classification2 categories
Active Exploitation
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-141
Patch1
2026-07-162
Active Exploitation2
Full discourse3 posts
  • Misbar | مسبار@MisbarSec
    Patch

    🚨 زيادة اختراقات وحملات إلكترونية عالمية ملخص الأسبوع: تقرير يكشف عن تصاعد الاختراقات الأمنية والإجراءات التنظيمية وتطورات الجريمة الإلكترونية حول العالم، مع التركيز على ثغرات CVE-2025-20337 و CVE-2025-5777. 💡 إجراءات الحماية: - تطبيق أحدث الـ Patches لهذه الثغرات فور توفرها. - مراجعة وتحديث سياسات أمن المعلومات بشكل دوري. - رفع مستوى الوعي لدى الموظفين بمخاطر الهجمات الإلكترونية. 🔗 https://thecyberexpress.com/weekly-roundup-cyber-express-feb-2026/ #الأمن_السيبراني #التهديدات_السيبرانية #CVE

    Post summary

    The post highlights recent cyber incidents and urges immediate patching of CVE-2025-20337 and CVE-2025-5777, with no evidence of PoC, exploit tools, or active exploitation.

    0003039
    50 followersView on X
  • CVE Brief@DailyCVEBrief
    Active Exploitation

    LOOK BACK: On July 16, 2025, CVE-2025-20337 shipped as a 'not exploited, not on KEV' CVSS 10.0 unauthenticated root RCE in Cisco ISE. Amazon later found an APT had already been exploiting it as a zero-day, before the CVE existed, chained with a Citrix bug. https://t.co/eQFKGWctI9

    Post summary

    The tweet reports that an APT was exploiting CVE‑2025‑20337 as a zero‑day before its formal CVE listing, indicating real‑world, active exploitation.

    10000137
    21 followersView on X
  • CVE Brief@DailyCVEBrief
    Active Exploitation

    Our full Look Back: the incomplete first patch, the enableStrongSwanTunnel root chain, and the in-memory webshell that trailed the KEV listing by weeks. https://cvebrief.com/cve/CVE-2025-20337/ https://t.co/tmt4hnamOh

    Post summary

    The tweet recounts real‑world exploitation of CVE-2025-20337 via an in‑memory webshell, notes an incomplete initial patch, and highlights activity that emerged after the KEV listing.

    0000010
    21 followersView on X
CPE platform detail18 entries

18 of 18 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--

Explore more