CVE-2026-20181Patch(cisco / identity_services_engine)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch cisco identity_services_engine systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_services_engine
  • identity_services_engine_passive_identity_connector

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 24 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 20 signals
  • Disclosure: 8 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 8 mentions (2026-06-18); latest day: 2
  • 24 total mentions across 7 days

Affected systems

Vendors
Products
identity_services_engineidentity_services_engine_passive_identity_connector

3 versions affected across 2 products

Deep dive

Activity timeline24 mentions / 7d
02468Mentions · 2026-04-22: 1Mentions · 2026-06-17: 4Mentions · 2026-06-18: 8Mentions · 2026-06-19: 4Mentions · 2026-06-24: 3Mentions · 2026-06-25: 2Mentions · 2026-07-15: 2PoC Mentioned / Linked · 2026-04-22: 1Patch / Workaround · 2026-06-17: 2Patch / Workaround · 2026-06-18: 5Patch / Workaround · 2026-06-19: 4Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-07-15: 2Technical Details · 2026-04-22: 1Technical Details · 2026-06-17: 4Technical Details · 2026-06-18: 7Technical Details · 2026-06-19: 3Technical Details · 2026-06-24: 2Technical Details · 2026-06-25: 1Technical Details · 2026-07-15: 204-2206-1706-1806-1906-2406-2507-15
Signal classification3 categories
Patch
1354.2%
Disclosure
833.3%
General
312.5%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-04-221
Disclosure1
2026-06-174
Disclosure3Patch1
2026-06-188
Disclosure2General1Patch5
2026-06-194
Disclosure1Patch3
2026-06-243
Disclosure1General1Patch1
2026-06-252
General1Patch1
2026-07-152
Patch2
Full discourse20 posts
  • starlabs@starlabs_sg
    Patch

    CVE-2026-20181 (CVSS 9.1 Critical) in Cisco ISE is now patched. RCE to root on the underlying OS. Found independently by @CurseRed and our former intern Tevel Sho. Proud of both of them. Around 25 or more to go. Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv

    Post summary

    The advisory announces that CVE-2026-20181, a critical RCE in Cisco ISE, is now patched and references the official Cisco security advisory.

    09145166.1K
    10.2K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    【セキュリティ ニュース】「Cisco ISE」にRCE脆弱性 - 端末の接続に影響するおそれも(1ページ目 / 全2ページ):Security NEXT https://www.security-next.com/186046 CVE-2026-20181/CVE-2026-20190 Cisco Identity Services Engineにおけるリモートコード実行および情報漏洩の脆弱性 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv

    Post summary

    Cisco issued an advisory for CVE‑2026‑20181 and CVE‑2026‑20190, detailing remote code execution and data leakage in Cisco Identity Services Engine and provided patch information, with no evidence of active exploitation or publishable PoC.

    010321.6K
    11.8K followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #Cisco released Security Updates to address multiple Vulnerabilities in Cisco Identity Services Engine (#ISE) and Cisco ISE Passive Identity Connector (#ISE-PIC). Apply Updates! #CVE-2026-20181 #CVE-2026-20190 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv

    Post summary

    Cisco has released security updates for CVE-2026-20181 and CVE-2026-20190 affecting their ISE products; users are urged to apply these patches to mitigate the vulnerabilities.

    00002277
    8.5K followersView on X
  • Divinmentis@Divinmentis
    Patch

    🚨 Cisco ISE patch watch: Cisco fixed CVE-2026-20181 and CVE-2026-20190 in ISE and ISE-PIC. The advisory says the flaws can enable remote code execution or sensitive information disclosure, with no workarounds. #Cisco #Cyber https://t.co/ElVl2jK4ES

    Post summary

    Cisco released patches for CVE-2026-20181 and CVE-2026-20190 in ISE and ISE‑PIC, addressing remote code execution and sensitive information disclosure with no available workarounds.

    2000078
    26 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected device.』 CVE-2026-20181 CVE-2026-20190 Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv

    Post summary

    Cisco disclosed CVE‑2026‑20181 and CVE‑2026‑20190 as remote code execution and information disclosure flaws in Identity Services Engine.

    10001563
    6.9K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Critical Cisco ISE vulnerabilities expose networks to Remote Code Execution (CVE-2026-20181) and data theft (CVE-2026-20190). Patch affected systems now. #CiscoISE #CyberSecurity #CVE202620181 #CVE202620190 #InfoSec https://securityonline.info/cisco-ise-vulnerabilities https://t.co/DhHIGCFdwU

    Post summary

    The tweet announces critical Cisco ISE vulnerabilities (CVE-2026-20181 and CVE-2026-20190) that allow remote code execution and data theft, and states that patches are now available for affected systems.

    00101460
    12.3K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE-2026-20181. 0day Intel: CVE-2026-20181 (CVSS 9.1 Critical) in Cisco ISE is now patched. RCE to root on t

    Post summary

    The text announces that CVE-2026-20181, a critical remote code execution vulnerability in Cisco ISE, has been identified and patched.

    1000073
    322 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Vendor v9.1. 0day Intel: CVE-2026-20181 (CVSS 9.1 Critical) in Cisco ISE is now patched.

    Post summary

    The text reveals that Cisco ISE’s critical vulnerability CVE-2026-20181 has been addressed with a patch.

    1000049
    322 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Cisco ISE の CVE-2026-20181/20190 が FIX:リモートコード実行の可能性 https://iototsecnews.jp/2026/06/18/critical-cisco-ise-vulnerability-allows-attacker-to-execute-malicious-code-remotely/ 今回の Cisco ISE の問題は、ユーザーから入力されたデータに対する不十分な検証や、不適切な認可チェックが原因で発生しました。それにより、認証情報などの機密データの漏洩や、リモートコマンド実行に至るリスクがあります。なお、回避策が存在しないため、パッチ適用が唯一の対策となります。ご利用のチームは、ご注意ください。 #Cisco #CVE202620181 #CVE202620190 #IdentityServicesEngine #Vulnerability

    Post summary

    The article reports that Cisco ISE CVE‑2026‑20181 and CVE‑2026‑20190, which allow remote code execution due to input validation and authorization flaws, have been fixed; the only available mitigation is applying the vendor patch.

    01000149
    501 followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「シスコシステムズのCisco Identity Services Engine (ISE)等の複数製品におけるパストラバーサルの脆弱性(CVE-2026-20181)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手… ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post offers a high‑level, three‑axis analysis of Cisco ISE’s path‑traversal vulnerability (CVE‑2026‑20181) but lacks technical details, exploit availability, or mitigation guidance.

    0000087
    846 followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「シスコシステムズのCisco Identity Services Engine (ISE)等の複数製品におけるパストラバーサルの脆弱性(CVE-2026-20181)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手… ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post references Cisco ISE’s CVE-2026-20181 path‑traversal flaw and links to a free analysis tool but provides no further technical, exploit, or remediation details.

    0000066
    858 followersView on X
  • ゆぅさん@YY20424277
    Disclosure

    【3軸解説】「シスコシステムズのCisco Identity Services Engine (ISE)等の複数製品におけるパストラバーサルの脆弱性(CVE-2026-20181)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手… ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post announces a path‑traversal vulnerability (CVE-2026‑20181) affecting Cisco ISE, providing basic details but no PoC, exploit code, active attack reports, or patch information.

    0000060
    858 followersView on X
  • Brainwork@brainworkblog
    Patch

    Cisco corrige falhas no ISE e ISE-PIC 🚨 A Cisco publicou em 17 de junho de 2026 um advisory sobre vulnerabilidades no ISE e no ISE-PIC que exigem atenção imediata das equipes técnicas. A CVE-2026-20181 pode permitir execução remota de código por um atacante autenticado com credenciais administrativas válidas. Já a CVE-2026-20190 pode expor informações sensíveis a um atacante remoto não autenticado. Além disso, a fabricante afirma que não há workarounds. Portanto, a resposta prática passa por validar a versão em uso, identificar a exposição a cada CVE e aplicar as correções indicadas no advisory. 🔐 Para ambientes que dependem do ISE para autenticação e controle de acesso, a atualização deve entrar no radar com prioridade. Detalhes no blog. #CiscoISE #SegurancaDaInformacao #Ciberseguranca #GestaoDeVulnerabilidades #PatchManagement

    Post summary

    Cisco released a patch advisory for two ISE vulnerabilities with detailed technical info, emphasizing no workarounds and the need to apply the recommended fixes.

    0000098
    575 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Cisco released security updates for critical CVE-2026-20181 and high-severity CVE-2026-20190 affecting Cisco ISE and Cisco ISE-PIC. Exploitation allows remote attackers to execute arbitrary code or access sensitive information. Patch Patch Patch https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv

    Post summary

    Cisco has issued patches for CVE‑2026‑20181 and CVE‑2026‑20190 that allow remote code execution or data access in ISE and ISE‑PIC, and the advisory directs readers to the patch URL.

    00000303
    7.2K followersView on X
  • Divinmentis@Divinmentis
    Disclosure

    @SecurityWeek Useful split: CVE-2026-20181 is admin-authenticated command execution, while CVE-2026-20190 is unauthenticated disclosure. With no workaround, patching should move with admin-plane exposure reduction, credential hygiene, and auth-log review. https://t.co/QtTJmCMvzP

    Post summary

    The tweet identifies the CVE impact vectors—admin‑authenticated command execution for CVE‑2026‑20181 and unauthenticated disclosure for CVE‑2026‑20190—and urges patching as the primary remediation step, noting no workaround is available.

    0000074
    26 followersView on X
  • Shah Sheikh@shah_sheikh
    Patch

    Cisco fixed a critical ISE vulnerability that lets attackers to gain root access: Cisco addressed CVE-2026-20181, a critical ISE vulnerability that lets authenticated admins execute commands and gain root access. Cisco addressed a critical command… https://securityaffairs.com/193849/uncategorized/cisco-fixed-a-critical-ise-vulnerability-that-lets-attackers-to-gain-root-access.html?utm_source=dlvr.it&utm_medium=twitter https://t.co/BEHYMkPQD1

    Post summary

    Cisco has released a patch for CVE‑2026‑20181, a critical flaw in ISE that permits authenticated administrators to execute commands as root. The vendor has addressed the issue with a fix.

    0000092
    2.3K followersView on X
  • Divinmentis@Divinmentis
    Disclosure

    🛰️ Source notes: Cisco rates CVE-2026-20181 critical at CVSS 9.1 and says exploitation requires valid administrative credentials. CVE-2026-20190 is unauthenticated information disclosure that can expose sensitive data such as hashed credentials. https://t.co/9Mq6ce698M

    Post summary

    The tweet announces Cisco’s assessment of CVE‑2026‑20181 as critical (CVSS 9.1) needing admin credentials, and notes CVE‑2026‑20190 as an unauthenticated info‑disclosure that could expose hashed credentials, without any PoC, exploit, patch or claim of active use.

    0000076
    26 followersView on X
  • UNDERCODE NEWS@UndercodeNews
    Patch

    🚨 #Cisco Issues Critical #CVE-2026-20181 Fix After Command Execution Flaw Threatens Identity Security Systems + Video -Fact Checker: ✅: 2 ❌: 1 || 2/3 → Score: 66% ⚖️ -Prediction: 📈 2 Positive | 📉 2 Negative http://undercodenews.com/cisco-issues-critical-cve-2026-20181-fix-after-command-execution-flaw-threatens-identity-security-systems-video/

    Post summary

    Cisco has released a fix for the critical CVE‑2026‑20181, a command execution flaw that could compromise identity security systems.

    0000079
    957 followersView on X
  • America's Pick@nims213
    Patch

    Critical Command Execution Vulnerability Patched in Cisco ISE https://ift.tt/r3bMoNx Cisco has released fixes for a critical-severity command execution vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Tracked as CVE-2026-20181 (C…

    Post summary

    Cisco has issued patches for CVE‑2026‑20181, a critical command‑execution vulnerability in ISE and ISE‑PIC, closing the security gap.

    0000076
    1.7K followersView on X
  • VulDB 🛡@vuldb
    General

    Attention, elevated activities detected targeting Cisco Identity Services Engine Software and ISE Passive Identity Connector (CVE-2026-20181) https://vuldb.com/vuln/372068/cti

    Post summary

    Short alert indicating elevated activity targeting CVE-2026-20181, but lacking PoC, exploit, patch, or technical details.

    0000094
    2.2K followersView on X
CPE platform detail40 entries

40 of 40 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoidentity_services_engine---
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.5.0--
Appciscoidentity_services_engine3.5.0--
Appciscoidentity_services_engine3.5.0--
Appciscoidentity_services_engine3.5.0--
Appciscoidentity_services_engine_passive_identity_connector---
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.3.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--

Explore more