CVE-2026-20147Disclosure(cisco / identity_services_engine)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cisco identity_services_engine systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node ISE deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_services_engine
  • identity_services_engine_passive_identity_connector

Threat summary

  • Patch or workaround signal is available
  • 20 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 15 signals
  • Disclosure: 11 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 6 mentions (2026-04-20); latest day: 1
  • 20 total mentions across 7 days

Affected systems

Vendors
Products
identity_services_engineidentity_services_engine_passive_identity_connector

5 versions affected across 2 products

Deep dive

Activity timeline20 mentions / 7d
02356Mentions · 2026-04-15: 2Mentions · 2026-04-16: 5Mentions · 2026-04-17: 2Mentions · 2026-04-18: 2Mentions · 2026-04-20: 6Mentions · 2026-04-23: 2Mentions · 2026-06-09: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-16: 2Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-04-20: 2Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 4Technical Details · 2026-04-17: 2Technical Details · 2026-04-18: 1Technical Details · 2026-04-20: 4Technical Details · 2026-04-23: 2Technical Details · 2026-06-09: 104-1504-1604-1704-1804-2004-2306-09
Signal classification3 categories
Disclosure
1155.0%
Patch
735.0%
General
210.0%
Referenced assets20 URLs
Classification over time
DateTotalLabels
2026-04-152
Disclosure1Patch1
2026-04-165
Disclosure3Patch2
2026-04-172
Disclosure1Patch1
2026-04-182
Disclosure1General1
2026-04-206
Disclosure3General1Patch2
2026-04-232
Disclosure1Patch1
2026-06-091
Disclosure1
Full discourse20 posts
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-20147(CVSS 9.9):Cisco ISE Remote Code Execution Vulnerability. 📊 812 Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Cisco%20ISE%22 👇Query HUNTER : http://product.name="Cisco ISE" 📰Refer:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ https://securityonline.info/cisco-ise-critical-rce-vulnerability-cve-2026-20147-root-access/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces the discovery of CVE‑2026‑20147, a high‑severity Remote Code Execution vulnerability in Cisco ISE, with CVSS 9.9 and links to official advisories.

    130074296.7K
    25.9K followersView on X
  • yousukezan@yousukezan
    Disclosure

    Cisco Identity Services Engine (ISE) に、CVSSスコア9.9という極めて重大なリモートコード実行(RCE)の脆弱性(CVE-2026-20147)が発見された。この脆弱性を悪用されると、攻撃者は管理者権限を介してシステムへのルートアクセスを確立する可能性がある。 https://securityonline.info/cisco-ise-critical-rce-vulnerability-cve-2026-20147-root-access/

    Post summary

    A critical remote code execution vulnerability (CVE-2026-20147) with a CVSS score of 9.9 has been discovered in Cisco Identity Services Engine, enabling attackers to potentially obtain root access through administrative privileges.

    0401752.4K
    14.3K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Cisco ISEで重大(Critical)な脆弱性3件が修正。CVE-2026-20147、CVE-2026-20180、CVE-2026-20186はCVSSスコア9.9で、1件目は認証後ユーザ、2、3件目は読取専用管理者ユーザが任意コマンドを実行可能なもの。 https://thecyberexpress.com/cisco-ise-vulnerabilities-enable-rce/

    Post summary

    Three critical Cisco ISE vulnerabilities (CVE‑2026‑20147, ‑20180, ‑20186) with CVSS 9.9 have been patched; the first allows authenticated users to run arbitrary commands, while the latter two enable read‑only admin users to execute arbitrary commands.

    010621.1K
    7.6K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🏢 أنظمة Enterprise: ⚙️ نظام Cisco ISE: التقييم: 9.9 | (CVE-2026-20147, 20180, 20186) ⚠️ تسمح للمستخدم الإداري بتنفيذ أوامر عن بُعد (RCE) وترقية الصلاحيات إلى Root. 📊 نظام SAP Business Planning: التقييم: 9.9 | (CVE-2026-27681) ⚠️ هجوم (SQL Injection) في ABAP يتيح التحكم بقواعد البيانات . 🔑 نظام Cisco Webex SSO: التقييم: 9.8 | (CVE-2026-20184) ⚠️ تخطي المصادقة الموحدة.

    Post summary

    The text announces high‑severity CVEs affecting Cisco ISE, SAP Business Planning, and Cisco Webex SSO, detailing RCE, SQL Injection, and authentication bypass vulnerabilities.

    100421.8K
    49.3K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    うわーいっぱいでてるるるるる Cisco Security Advisories https://sec.cloudapps.cisco.com/security/center/publicationListing.x CVE-2026-20184 Cisco Webex Services Certificate Validation Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL CVE-2026-20147 CVE-2026-20148 Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ CVE-2026-20180 CVE-2026-20186 Cisco Identity Services Engine Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv 【セキュリティ ニュース】「Cisco ISE」に複数の深刻な脆弱性 - 一部修正パッチを準備中(1ページ目 / 全2ページ):Security NEXT https://www.security-next.com/183510

    Post summary

    The post lists several Cisco CVEs with advisory links, noting that patches for some are being prepared, but does not provide further technical details or exploitation evidence.

    000421.3K
    11.7K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Cisco patches critical ISE vulnerabilities (CVE-2026-20147, CVE-2026-20180, CVE-2026-20186) enabling remote code execution, root access, and privilege escalation in Identity Services Engine and Webex Services. #CiscoISE #RemoteCode #USA https://ift.tt/mMQ93Gu

    Post summary

    Cisco has released patches for three critical ISE vulnerabilities that allow remote code execution, root access, and privilege escalation; no PoC or exploit code is disclosed.

    01020294
    4.4K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『We reported this issue to Cisco after it had already been received from another reporter,』 (CVE-2026-20147) Cisco Identity Services Engine Authenticated Command Injection in Deployment-RPC Leading to Remote Code Execution https://starlabs.sg/advisories/26/26-20147/

    Post summary

    The author reported CVE‑2026‑20147 to Cisco; the vulnerability is an authenticated command injection that can lead to remote code execution, as outlined in the linked advisory.

    00011491
    6.9K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Cisco ISE/ISE-PIC の脆弱性 CVE-2026-20147 が FIX:認証済みフル RCE の恐れ https://iototsecnews.jp/2026/04/16/critical-cisco-ise-flaws-let-remote-attackers-execute-malicious-code/ 今回の緊急アドバイザリの内容は、ネットワークの認証管理を担う Cisco ISE の管理画面において、ユーザーが入力したデータに対する検証の不備の修正です。最も深刻な CVE-2026-20147 (CVSS 9.9) は、悪意のリクエストに対するブロックの不備により、攻撃者に対してサーバの基盤となる OS の操作を許すものです。たとえ操作に管理者権限が必要であっても、一度侵入を許せば最高権限である root 奪取やシステム停止にまで発展する恐れがあるため、その影響は壊滅的です。また、CVE-2026-20148 では、本来アクセスできないはずのディレクトリへの不正アクセスが生じます。ご利用のチームは、ご注意ください。 #Cisco #CVE202620147 #CVE202620148 #ISE #ISEPIC #Vulnerability

    Post summary

    Cisco ISE is affected by CVE-2026-20147, a high‑severity RCE flaw that could lead to root takeover, and a patch has been released to address the input validation issue.

    01000151
    486 followersView on X
  • z3n@zench4n
    General

    Treat agent tool-use like remote code execution. Just as CVE-2026-20147 shows how authenticated attackers can exploit Cisco ISE, an agent with excessive permissions can become a proxy for lateral movement. If the agent can call a shell, the system is compromised.

    Post summary

    The statement references CVE‑2026‑20147 and general lateral‑movement concerns but offers no substantive technical insights or actionable information.

    1000012
    1.5K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple critical vuln in #CISCO #ISE CVE-2026-20186, CVE-2026-20147, CVE-2026-20180 CVSS: 9.9.Exploliting them can lead to Denial of Service #DoS and Remote Code Execution #RCE by unauthenticated remote threat actors https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-cisco-ise-can-lead-rce-patch-immediately #Patch #Patch #Patch

    Post summary

    This post warns about three critical Cisco ISE CVEs (CVSS 9.9) that can lead to DoS and RCE, and urges immediate patching via the provided advisory.

    01000195
    7.2K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Patch

    🚨 Cisco Webex & ISE Critical Vulnerabilities (CVE-2026-20184, CVE-2026-20147, CVE-2026-20180, CVE-2026-20186) SSO auth bypass + input validation flaws → user impersonation + remote code execution 💡 Lesson: Identity systems are high-value targets — one flaw = full system compromise ⚠️ Action: Update Cisco ISE immediately + rotate SSO certificates, don’t delay patching critical auth systems https://thehackernews.com/2026/04/cisco-patches-four-critical-identity.html

    Post summary

    The tweet alerts about four critical Cisco CVEs, highlighting auth bypass, input‑validation, and RCE flaws, and urges immediate patching and certificate rotation to mitigate the vulnerabilities.

    01000193
    6.2K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-20147 — CVSS 9.9/10 ██████████ A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/0nAwxFdbKs

    Post summary

    The tweet announces a critical Cisco ISE vulnerability (CVE-2026-20147) with a CVSS score of 9.9/10 and urges patching, but provides no PoC, exploit, or evidence of active exploitation.

    1000063
    23 followersView on X
  • UWillC@uwillc
    Disclosure

    CVE-2026-20147/180/186 (ISE, 9.9, Apr 15): read-only admin = root. CVE-2026-20184 (Webex, 9.8): SSO auth bypass. CVE-2026-20127 (SD-WAN, 10.0): Talos traces exploitation to 2023. March-September bundle model is dead.

    Post summary

    The text lists multiple CVEs with their severity scores, affected products, and brief vulnerability descriptors (privilege escalation, SSO bypass). No PoC, exploit tool, patch, or ongoing exploitation is reported.

    0000054
    504 followersView on X
  • AllCy@all_cyb
    Disclosure

    🚨 ALERTA RÁPIDA 🔐 CVE-2026-20147 — Cisco Identity Services Engine (ISE) #Cisco #ISE #Vulnerability #Cybersecurity #AllCy https://www.linkedin.com/posts/allcy_alerta-r%C3%A1pida-cve-2026-20147-cisco-activity-7452057285675134977-qBU3

    Post summary

    The post is a brief alert announcing the existence of CVE‑2026‑20147 affecting Cisco Identity Services Engine. No additional technical details, exploit evidence, or mitigation information are provided.

    0000042
    1 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Cisco ❗ CVE-2026-20186 ❗ CVE-2026-20184 ❗ CVE-2026-20147 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cisco-14/ https://t.co/43iRTTwbX3

    Post summary

    The tweet announces three Cisco CVEs and links to a source for more information, but provides no details on exploits, patches, or technical aspects.

    00000122
    6.7K followersView on X
  • Yemi | アディエミ@aiithingsai
    Disclosure

    CVE-2026-20147 in Cisco ISE: CVSS 9.9. Authenticated attacker sends a crafted HTTP request, gets user-level OS access, escalates to root. Read-only admin creds are enough to trigger it. All ISE 3.1 through 3.5 affected. No public PoC yet — but that clock is ticking.

    Post summary

    The post announces a high‑severity CVE (CVE‑2026‑20147) in Cisco ISE 3.1‑3.5, outlining how an authenticated attacker can craft an HTTP request to gain root access. No PoC, patch, or active exploitation information is provided.

    0000090
    99 followersView on X
  • DLTA@DLTA_Sec
    Disclosure

    @SCMagazine @Cisco CVE-2026-20147 at CVSS 9.9 sits on the identity plane. Custodians and exchanges running ISE for workforce access have signing-key-adjacent exposure; patch window is the control gap.

    Post summary

    The tweet from @SCMagazine and @Cisco announces CVE-2026-20147, a high‑severity CVSS 9.9 vulnerability impacting the identity plane with signing‑key adjacency, and highlights the need for a patch to close the control gap.

    0000071
    484 followersView on X
  • Techgines@nxtgen579255
    Disclosure

    The pattern matters as much as the patch. Last time it was Cisco IMC — hardware mgmt plane auth bypass (CVE-2026-20093). This time it's ISE — the identity mgmt plane. The attack surface is moving up the stack. The isn't changing. https://www.techgines.com/post/cisco-ise-cve-2026-20147-webex-critical-vulnerabilities-rce https://t.co/vigXUq2HNa

    Post summary

    The text announces a new Cisco ISE authentication bypass vulnerability (CVE‑2026‑20147), referencing a link for further details, but it does not provide any PoC, exploit, patch, or evidence of active exploitation.

    0000072
    4 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20147 A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an af… https://www.cve.org/CVERecord?id=CVE-2026-20147

    Post summary

    The text announces CVE‑2026‑20147, an authenticated remote‑code‑execution flaw in Cisco ISE and ISE‑PIC that allows execution of arbitrary OS commands; it contains no PoC, exploit, patch, or active exploitation details.

    00000144
    57.2K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Cisco Identity Services Engine Software and ISE Passive Identity Connector (CVE-2026-20147) https://vuldb.com/vuln/357741

    Post summary

    A newly disclosed, critically-rated vulnerability (CVE-2026-20147) was identified in Cisco Identity Services Engine Software and the ISE Passive Identity Connector.

    0000084
    2.1K followersView on X
CPE platform detail81 entries

81 of 81 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoidentity_services_engine---
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.1.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.5.0--
Appciscoidentity_services_engine3.5.0--
Appciscoidentity_services_engine3.5.0--
Appciscoidentity_services_engine_passive_identity_connector---
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.1.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.2.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--

Explore more