Cisco released multiple security advisories on September 16, 2026, addressing critical Cisco ISE vulnerabilities across enterprise deployments. These defects allow remote attackers to bypass authentication, inject arbitrary operating system commands, and seize root control. Therefore, system administrators must install the latest patches immediately to secure network access environments.
- Total: 5 CVEs
- Severity: 5 Critical
- Actively exploited: None confirmed
- Highest severity: 10.0 (Critical · CVSSv3) — CVE-2026-76423
- Action: Apply the latest security updates now
Track every Cisco CVE the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-76423 | 10 | ISE API Authentication Bypass | Not exploited |
| CVE-2026-20130 | 10 | Identity Services Engine Hardening Release - Improper Neutralization | Not exploited |
| CVE-2026-20307 | 9.9 | Identity Services Engine Remote Code Execution | Not exploited |
| CVE-2026-20305 | 9.1 | Identity Services Engine Command Injection | Not exploited |
| CVE-2026-20284 | 9.1 | Identity Search Engine SXP REST API SQL Injection | Not exploited |
Why This Threat Matters
Sourced estimates show that tens of thousands of organizations deploy Cisco Identity Services Engine to manage identity policies. The platform controls corporate network admission for employees, devices, and visitors. Consequently, flaws within this infrastructure threaten the entire trust boundary of an enterprise.
If attackers compromise the central identity server, they can alter access rules and monitor internal traffic. Furthermore, intruders can pivot across corporate networks without triggering typical perimeter alarms. Attackers can also cause denial-of-service conditions that block all unauthenticated endpoints from accessing business networks.
How the Attacks Work
The disclosed flaws cover multiple weakness categories across web interfaces and background services. In addition, the vendor’s Cisco ISE hardening release documents extensive internal security findings. According to Cisco, “These vulnerabilities were found during internal security testing using existing testing processes as well as frontier AI models.”
First, CVE-2026-76423 allows unauthenticated remote attackers to gain administrative access via the REST API. The vendor confirmed, “This vulnerability is due to the REST API web service being exposed with insufficient authorization checks.” Attackers can read and alter identity data through crafted HTTP requests. Detailed disclosures are available in the Cisco multi-vulnerability advisory.
Second, multiple flaws permit remote code execution. Under CVE-2026-20307, attackers send serialized Java objects to the web interface to trigger insecure deserialization. Meanwhile, CVE-2026-20176 enables command execution through invalid HTTP input validation. You can inspect these mechanisms in the Cisco remote code execution advisory.
Additionally, researchers discovered critical command injection vectors in diagnostic tools and API endpoints. The advisory notes, “A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.” Teams can examine these flaws in the Cisco command injection report.
Finally, CVE-2026-20284 introduces SQL injection into the SXP REST API. Cisco outlined this database risk in an authenticated API vulnerability bulletin. Public discussion exists for some flaws, but Cisco has not observed malicious exploitation of these specific CVEs.
Affected Versions
These Cisco ISE vulnerabilities impact software releases 3.1, 3.2, 3.3, 3.4, and 3.5. Furthermore, several issues affect Cisco ISE Passive Identity Connector across all device configurations.
Patch and Mitigation Steps
Administrators must update their deployments to patched releases immediately to remediate these Cisco ISE vulnerabilities. Cisco released 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. Organizations running older versions should migrate to a supported release.
There are no complete workarounds for these vulnerabilities. However, network teams can apply infrastructure access control lists to limit management traffic. Administrators should restrict access strictly to trusted internal subnets.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!