Cisco Identity Services Engine... Note

Cisco Identity Services Engine Command Injection Vulnerabilities

Multiple critical vulnerabilities have been discovered in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). These flaws could enable an authenticated, remote attacker to execute arbitrary commands with root privileges. To successfully exploit these vulnerabilities, the attacker must possess valid administrative credentials. Cisco has released software updates that resolve these security issues. Unfortunately, there are no temporary workarounds available to mitigate these vulnerabilities. This advisory is part of a larger release of security advisories from Cisco. Further details on these specific vulnerabilities can be found in the advisory's details section. Affected products include both Cisco ISE and ISE-PIC. The security impact rating for these vulnerabilities is classified as critical. The associated CVE identifiers are CVE-2026-20305 and CVE-2026-20306.