Skip to content

CVE-2026-20307 CVE-2026-20176 CVE-2026-20211

Cisco Identity Services Engine remote code execution vulnerabilities (CVE-2026-20307, CVE-2026-20176, CVE-2026-20211)

Critical 9.9 Vendor: Cisco Published

Three critical vulnerabilities in Cisco Identity Services Engine allow authenticated administrators to run commands on the underlying operating system. No workarounds exist; Cisco has released fixes. Restrict management access and apply the vendor update.

What happened

Three vulnerabilities affect the web-based management interface of Cisco Identity Services Engine (ISE). CVE-2026-20307 allows an authenticated remote attacker with at least low-privileged administrative credentials to send a crafted serialised Java object that is insecurely deserialised, execute arbitrary commands, and elevate privileges to root. CVE-2026-20176 and CVE-2026-20211 require valid high-privileged administrative credentials; one arises from insufficient validation of user-supplied input via a crafted HTTP request, the other from insecure deserialisation of Java objects. Both can lead to system-level or user-level access followed by elevation to root.

All three are exploitable over the network with no user interaction. In single-node deployments, successful exploitation can make the affected ISE node unavailable, creating a denial-of-service condition in which endpoints that have not already authenticated cannot access the network until the node is restored. Cisco PSIRT has stated it is not aware of public announcements or malicious use; the vulnerabilities are not publicly disclosed.

Who is affected

The affected product is Cisco Identity Services Engine Software. The listed affected versions are 3.1.0 and 3.1.0 p1 through p5, and 3.2.0 and 3.2.0 p1. ISE is typically deployed on premises as the policy and access control point for network authentication, so organisations using it to control wired, wireless or VPN access should treat this as directly relevant. Single-node deployments carry additional availability risk, as a successful exploit can deny network access to not-yet-authenticated endpoints.

What to do now

  1. Review Cisco's advisory cisco-sa-ise-rce-se7bYU57 and confirm the fixed software release for your deployment; the specific fixed versions are not listed on this page. Apply the vendor fix as soon as practical.
  2. There are no workarounds. Until patching is complete, restrict access to the ISE web management interface to trusted management networks, require multi-factor authentication for administrative accounts, and review all administrative users for unexpected or orphaned credentials.
  3. After patching, check for unauthorised configuration changes and audit administrative activity.

How to detect it

Cisco has not published specific indicators of compromise. As a priority, verify that the ISE management interface is not reachable from untrusted network segments and that administrative accounts are current and limited. Monitor administrative logs for unexpected configuration changes, newly created accounts, or unusual requests to the management interface.

Beyond the patch

Beyond patching, ISE sits at the centre of network access, so its management plane deserves the same segmentation and monitoring as critical infrastructure. Our Implementation & Assessment Services can test ISE deployments for the injection and deserialisation issues that allow this class of weakness to persist, while Managed Detection & Response (MDR) is positioned to catch the post-exploitation activity — privilege escalation, command execution and credential abuse — that follows an administrative compromise.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-20307
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-20176
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet
CVE-2026-20211
Cisco Identity Services Engine Software
3.1.0
3.1.0 p1
3.1.0 p3
3.1.0 p2
3.2.0
3.1.0 p4
3.1.0 p5
3.2.0 p1
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.