Skip to content

CVE-2026-20192 CVE-2026-20130 CVE-2026-20234 CVE-2026-20194 CVE-2026-20237 CVE-2026-20287

Cisco Identity Services Engine hardening release addresses multiple critical vulnerabilities (CVE-2026-20192 and others)

Critical 10.0 Vendor: Cisco Published

Cisco Identity Services Engine and ISE-PIC have received a hardening release for several critical vulnerabilities, some reachable over the network without credentials. Apply Cisco's September 2026 release; no workarounds are available.

What happened

Cisco has published a software hardening release for Cisco Identity Services Engine and Cisco ISE Passive Identity Connector following an internal security review. The release groups vulnerabilities under improper access control, improper neutralisation of special elements, insufficiently protected credentials, incorrect resource transfer between spheres, input validation, and privilege management weaknesses.

The most severe entries, CVE-2026-20192 and CVE-2026-20130, carry CVSS scores of 10 and can be exploited over the network with no credentials and no user interaction. Successful exploitation can affect confidentiality, integrity, and availability, with scope changing to other system components. Others are also critical and network-reachable, requiring low or high privileges but no user interaction. CVE-2026-20287 has a CVSS score of 6.5, requires high privileges, and has high confidentiality and integrity impact with no availability impact.

Cisco PSIRT states it is not aware of public announcements or malicious use of the described vulnerabilities, and there are no workarounds.

Who is affected

Cisco Identity Services Engine Software versions 3.1.0, 3.1.0 p1, 3.1.0 p2, 3.1.0 p3, 3.1.0 p4, 3.1.0 p5, 3.2.0, and 3.2.0 p1 are affected. Cisco ISE Passive Identity Connector versions 3.1.0, 3.2.0, 3.3.0, 3.4.0, and 3.5.0 are affected. If you run Cisco ISE as an identity and access policy engine, or ISE-PIC for agentless identity mapping, check whether these builds are in use and treat this as a priority.

What to do now

  1. Apply Cisco's September 2026 hardening release. A fix is available, but the advisory record does not list specific fixed version numbers, so confirm the correct build for your branch through Cisco Identity Services Engine Hardening Release: September 2026.
  2. Prioritise installations that are reachable from untrusted or less-trusted network segments. The critical issues can be triggered over the network without credentials, so an exposed administration or service interface is the immediate concern.
  3. There are no workarounds. While planning the update, restrict access to affected systems to the smallest possible set of trusted administrative networks.
  4. After updating, verify that the system reports the hardening build and re-check access to management interfaces.

How to detect it

Cisco has not published indicators of compromise for these issues, and Cisco PSIRT states it is not aware of public announcements or malicious use. Because the most severe entries are reachable over the network without user interaction, begin by identifying which ISE and ISE-PIC interfaces are reachable from untrusted networks. Unauthenticated remote access is the exposure these releases close.

Beyond the patch

These findings are a reminder that identity infrastructure is often reachable from more networks than intended, and the critical entries here can be exploited without credentials. After patching, it is worth having the same view of exposure that the CVSS vectors describe. Our Virtual CISO Services (vCISO) can help you map and reduce exposed management interfaces, and Supply Chain Defense & Third-Party Risk can keep visibility of security advisories for the identity products you depend on.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-20192
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-20192
Cisco ISE Passive Identity Connector
3.2.0
3.1.0
3.3.0
3.4.0
3.5.0
No fixed version listed yet
CVE-2026-20130
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-20130
Cisco ISE Passive Identity Connector
3.2.0
3.1.0
3.3.0
3.4.0
3.5.0
No fixed version listed yet
CVE-2026-20234
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-20234
Cisco ISE Passive Identity Connector
3.2.0
3.1.0
3.3.0
3.4.0
3.5.0
No fixed version listed yet
CVE-2026-20194
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-20194
Cisco ISE Passive Identity Connector
3.2.0
3.1.0
3.3.0
3.4.0
3.5.0
No fixed version listed yet
CVE-2026-20237
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-20237
Cisco ISE Passive Identity Connector
3.2.0
3.1.0
3.3.0
3.4.0
3.5.0
No fixed version listed yet
CVE-2026-20287
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-20287
Cisco ISE Passive Identity Connector
3.2.0
3.1.0
3.3.0
3.4.0
3.5.0
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.