CVE-2026-20180Patch(cisco / identity_services_engine)

MEDIUMCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch cisco identity_services_engine systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node ISE deployments, successful exploitation of these vulnerabilities could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_services_engine

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 13 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 5 mentions (2026-04-16); latest day: 1
  • 14 total mentions across 6 days

Affected systems

Vendors
Products
identity_services_engine

3 versions affected across 1 product

Deep dive

Activity timeline14 mentions / 6d
01345Mentions · 2026-04-15: 1Mentions · 2026-04-16: 5Mentions · 2026-04-17: 2Mentions · 2026-04-20: 2Mentions · 2026-04-21: 3Mentions · 2026-05-01: 1PoC Mentioned / Linked · 2026-04-21: 1Exploit Tool / Code · 2026-04-21: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-16: 2Patch / Workaround · 2026-04-17: 2Patch / Workaround · 2026-04-20: 2Patch / Workaround · 2026-04-21: 3Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 5Technical Details · 2026-04-17: 2Technical Details · 2026-04-20: 2Technical Details · 2026-04-21: 304-1504-1604-1704-2004-2105-01
Signal classification4 categories
Patch
857.1%
Disclosure
321.4%
General
214.3%
Exploit
17.1%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-04-151
Patch1
2026-04-165
Disclosure3General1Patch1
2026-04-172
Patch2
2026-04-202
Patch2
2026-04-213
Exploit1Patch2
2026-05-011
General1
Full discourse14 posts
  • kokumօtօ@__kokumoto
    Patch

    Cisco ISEで重大(Critical)な脆弱性3件が修正。CVE-2026-20147、CVE-2026-20180、CVE-2026-20186はCVSSスコア9.9で、1件目は認証後ユーザ、2、3件目は読取専用管理者ユーザが任意コマンドを実行可能なもの。 https://thecyberexpress.com/cisco-ise-vulnerabilities-enable-rce/

    Post summary

    Cisco ISE has patched three critical CVEs with CVSS 9.9 that allowed arbitrary command execution after authentication; the article focuses on the available fix.

    010621.1K
    7.6K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    うわーいっぱいでてるるるるる Cisco Security Advisories https://sec.cloudapps.cisco.com/security/center/publicationListing.x CVE-2026-20184 Cisco Webex Services Certificate Validation Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL CVE-2026-20147 CVE-2026-20148 Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ CVE-2026-20180 CVE-2026-20186 Cisco Identity Services Engine Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv 【セキュリティ ニュース】「Cisco ISE」に複数の深刻な脆弱性 - 一部修正パッチを準備中(1ページ目 / 全2ページ):Security NEXT https://www.security-next.com/183510

    Post summary

    Cisco has publicly disclosed multiple new vulnerabilities in Webex Services and Identity Services Engine, with some patches currently being prepared.

    000421.3K
    11.7K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Cisco patches critical ISE vulnerabilities (CVE-2026-20147, CVE-2026-20180, CVE-2026-20186) enabling remote code execution, root access, and privilege escalation in Identity Services Engine and Webex Services. #CiscoISE #RemoteCode #USA https://ift.tt/mMQ93Gu

    Post summary

    Cisco has released patches for three critical ISE and Webex vulnerabilities that allowed remote code execution, root access, and privilege escalation.

    01020294
    4.4K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Exploit

    🚨 UPDATE — CVE-2026-20180 Cisco ISE Remote Code Execution — exploit now public CVSS 9.9 ⚡ Public PoC on GitHub (Apr 21) ✅ Cisco patch available (Apr 15) Full analysis → https://sec.kaitan.id/cves/CVE-2026-20180 #Cisco #ISE #CyberSecurity

    Post summary

    CVE‑2026‑20180 is a high‑severity remote code execution flaw in Cisco ISE, with a public PoC and exploit now available on GitHub; Cisco has released a patch to address it.

    0101039
    124 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-20180 — CVSS 9.9/10 ██████████ A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/WJLywJ5Cif

    Post summary

    Cisco Identity Services Engine (ISE) is vulnerable to CVE‑2026‑20180, allowing authenticated remote attackers to execute code; a patch has already been released.

    2000060
    23 followersView on X
  • RedLegg@RedLegg
    Patch

    Security Bulletin: Cisco ISE (CVE-2026-20180, CVSS 9.9) allows authenticated RCE via crafted HTTP requests. Patch immediately. #ThreatIntel #RedLeggCTI https://hubs.ly/Q04cTsBp0

    Post summary

    The bulletin alerts that Cisco ISE CVE‑2026‑20180 is a high‑severity authenticated RCE; immediate patching is recommended.

    00010113
    2.2K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple critical vuln in #CISCO #ISE CVE-2026-20186, CVE-2026-20147, CVE-2026-20180 CVSS: 9.9.Exploliting them can lead to Denial of Service #DoS and Remote Code Execution #RCE by unauthenticated remote threat actors https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-cisco-ise-can-lead-rce-patch-immediately #Patch #Patch #Patch

    Post summary

    This advisory highlights three critical Cisco ISE CVEs (CVE‑2026‑20186, CVE‑2026‑20147, CVE‑2026‑20180) with a CVSS score of 9.9 that can enable DoS and remote code execution, and urges users to apply the available patch immediately.

    01000195
    7.2K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Patch

    🚨 Cisco Webex & ISE Critical Vulnerabilities (CVE-2026-20184, CVE-2026-20147, CVE-2026-20180, CVE-2026-20186) SSO auth bypass + input validation flaws → user impersonation + remote code execution 💡 Lesson: Identity systems are high-value targets — one flaw = full system compromise ⚠️ Action: Update Cisco ISE immediately + rotate SSO certificates, don’t delay patching critical auth systems https://thehackernews.com/2026/04/cisco-patches-four-critical-identity.html

    Post summary

    The post highlights four critical Cisco vulnerabilities and urges immediate patching of Cisco ISE along with SSO certificate rotation, focusing on remediation rather than detailing exploit code or active attacks.

    01000193
    6.2K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-20180: Cisco ISE Remote Code Execution Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04f7pSv0

    Post summary

    The provided text gives only the CVE identifier and an article title, with no evidence of proof-of-concept, exploit code, active exploitation, patch, technical details, or false-positive claims.

    0000066
    29 followersView on X
  • the SE@theSEalpha
    Patch

    🚨 Cisco ISE CVSS 9.9 RCE (CVE-2026-20180/20186): "Read-only" admin creds → full compromise via crafted HTTP. True Zero Trust rejects role assumptions—least privilege + behavioral analytics every access. Patch now. #CiscoISE #ZeroTrust #PatchTuesday

    Post summary

    A new high‑severity RCE in Cisco ISE (CVE‑2026‑20180/20186) is disclosed with a patch immediately available.

    0000035
    12 followersView on X
  • the SE@theSEalpha
    Patch

    🚨 Cisco patches critical ISE flaws (CVE-2026-20180/20186, CVSS 9.9): read-only admin creds → RCE via crafted HTTP. Zero Trust: Validate inputs rigorously in identity services. Patch now. https://thehackernews.com/2026/04/cisco-patches-four-critical-identity.html

    Post summary

    Cisco issued patches for critical ISE flaws CVE-2026-20180/20186 (CVSS 9.9) that allow RCE via crafted HTTP requests; users are urged to apply the updates immediately.

    0000068
    9 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Cisco warns two new ISE flaws CVE-2026-20186 and CVE-2026-20180 let Read Only Admins run OS commands, potentially escalating to root and causing DoS in single-node deployments. https://threatcluster.io/cluster/cisco-ise-vulnerabilities-cve-2026-20186-and-cve-2026-20180--ff7c9812

    Post summary

    Cisco has announced two newly discovered ISE vulnerabilities (CVE‑2026‑20186 and CVE‑2026‑20180) that allow read‑only administrators to execute OS commands, potentially escalating privileges to root and causing denial of service in single‑node deployments.

    0000060
    155 followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-5598 | CVSS 10.0 🔴 CVE-2026-6349 | CVSS 10.0 🔴 CVE-2026-20180 | CVSS 9.9 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists three CVEs with high CVSS scores but offers no additional technical details, exploits, or remediation guidance.

    0000065
    5.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20180 A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system… https://www.cve.org/CVERecord?id=CVE-2026-20180

    Post summary

    The CVE-2026-20180 vulnerability in Cisco Identity Services Engine allows authenticated remote attackers to execute arbitrary OS commands, but no PoC, exploit, patch, or active exploitation is reported.

    00000115
    57.2K followersView on X
CPE platform detail21 entries

21 of 21 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoidentity_services_engine---
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--

Explore more