CVE-2026-20186Patch(cisco / identity_services_engine)

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch cisco identity_services_engine systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node ISE deployments, successful exploitation of these vulnerabilities could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_services_engine

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-04-16); latest day: 2
  • 10 total mentions across 4 days

Affected systems

Vendors
Products
identity_services_engine

3 versions affected across 1 product

Deep dive

Activity timeline10 mentions / 4d
01234Mentions · 2026-04-15: 3Mentions · 2026-04-16: 4Mentions · 2026-04-17: 1Mentions · 2026-04-20: 2Patch / Workaround · 2026-04-15: 2Patch / Workaround · 2026-04-16: 2Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-04-15: 2Technical Details · 2026-04-16: 4Technical Details · 2026-04-17: 1Technical Details · 2026-04-20: 104-1504-1604-1704-20
Signal classification3 categories
Patch
550.0%
Disclosure
440.0%
General
110.0%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-04-153
Disclosure2Patch1
2026-04-164
Disclosure2Patch2
2026-04-171
Patch1
2026-04-202
General1Patch1
Full discourse10 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    うわーいっぱいでてるるるるる Cisco Security Advisories https://sec.cloudapps.cisco.com/security/center/publicationListing.x CVE-2026-20184 Cisco Webex Services Certificate Validation Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL CVE-2026-20147 CVE-2026-20148 Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ CVE-2026-20180 CVE-2026-20186 Cisco Identity Services Engine Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv 【セキュリティ ニュース】「Cisco ISE」に複数の深刻な脆弱性 - 一部修正パッチを準備中(1ページ目 / 全2ページ):Security NEXT https://www.security-next.com/183510

    Post summary

    The post catalogs multiple Cisco CVEs with details of Remote Code Execution and Path Traversal flaws, references Cisco advisories, and notes that patches are in preparation.

    000421.3K
    11.7K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Cisco patches critical ISE vulnerabilities (CVE-2026-20147, CVE-2026-20180, CVE-2026-20186) enabling remote code execution, root access, and privilege escalation in Identity Services Engine and Webex Services. #CiscoISE #RemoteCode #USA https://ift.tt/mMQ93Gu

    Post summary

    Cisco has released patches for three critical ISE vulnerabilities (CVE‑2026‑20147, CVE‑2026‑20180, CVE‑2026‑20186) that enable remote code execution, root access, and privilege escalation.

    01020294
    4.4K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple critical vuln in #CISCO #ISE CVE-2026-20186, CVE-2026-20147, CVE-2026-20180 CVSS: 9.9.Exploliting them can lead to Denial of Service #DoS and Remote Code Execution #RCE by unauthenticated remote threat actors https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-cisco-ise-can-lead-rce-patch-immediately #Patch #Patch #Patch

    Post summary

    The advisory highlights three critical Cisco ISE CVEs (CVSS 9.9) that enable DoS and RCE, and urges organizations to apply the available patch immediately.

    01000195
    7.2K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Patch

    🚨 Cisco Webex & ISE Critical Vulnerabilities (CVE-2026-20184, CVE-2026-20147, CVE-2026-20180, CVE-2026-20186) SSO auth bypass + input validation flaws → user impersonation + remote code execution 💡 Lesson: Identity systems are high-value targets — one flaw = full system compromise ⚠️ Action: Update Cisco ISE immediately + rotate SSO certificates, don’t delay patching critical auth systems https://thehackernews.com/2026/04/cisco-patches-four-critical-identity.html

    Post summary

    Cisco Webex and ISE vulnerabilities expose SSO bypass leading to user impersonation and RCE; users should update Cisco ISE immediately and rotate SSO certificates to mitigate the threat.

    01000193
    6.2K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-20186 — CVSS 9.9/10 ██████████ A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/gR0XMRGj9l

    Post summary

    The tweet announces the critical CVE-2026-20186 with a CVSS of 9.9 and urges users to apply the patch immediately.

    1000048
    23 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Cisco ❗ CVE-2026-20186 ❗ CVE-2026-20184 ❗ CVE-2026-20147 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cisco-14/ https://t.co/43iRTTwbX3

    Post summary

    The message lists three Cisco CVEs and points to external links for more information, but offers no details on exploitation, patches, or technical specifics.

    00000122
    6.7K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Cisco warns two new ISE flaws CVE-2026-20186 and CVE-2026-20180 let Read Only Admins run OS commands, potentially escalating to root and causing DoS in single-node deployments. https://threatcluster.io/cluster/cisco-ise-vulnerabilities-cve-2026-20186-and-cve-2026-20180--ff7c9812

    Post summary

    Cisco has announced two new ISE vulnerabilities that allow read‑only administrators to execute OS commands, potentially escalating privileges and causing denial‑of‑service.

    0000060
    155 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20186 A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system… https://www.cve.org/CVERecord?id=CVE-2026-20186

    Post summary

    The post announces CVE-2026-20186, a Cisco ISE flaw that allows authenticated remote execution of OS commands, without mention of exploitation or remediation.

    00000131
    57.2K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Cisco Identity Services Engine Software (CVE-2026-20186) https://vuldb.com/vuln/357743

    Post summary

    A severe vulnerability (CVE-2026-20186) has been disclosed for Cisco Identity Services Engine Software, but no additional PoC, exploitation details, or patch information is provided.

    0000055
    2.1K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-20186 A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitr… CVSS 9.9 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-20186 #Cisco #CyberSecurity #InfoSec

    Post summary

    The post announces the critical CVE‑2026‑20186 in Cisco ISE, noting an authenticated remote code‑execution risk with a CVSS of 9.9 and no patch available, but it offers no PoC, exploit code, or evidence of active exploitation.

    000001
    145 followersView on X
CPE platform detail21 entries

21 of 21 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoidentity_services_engine---
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.2.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.3.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--

Explore more