Executive brief
Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector contain critical vulnerabilities related to improper handling of special elements in output, which can enable command injection, cross-site scripting, and code injection attacks. An attacker with network access can exploit these flaws to gain complete control over the system, potentially compromising the authentication and authorization infrastructure of an entire enterprise network. One of the related vulnerabilities is known to be actively exploited in the wild.
Technical details
The vulnerability is classified as CWE-74 (Improper Neutralization of Special Elements in Output) and encompasses command injection, cross-site scripting (XSS), XML injection, code injection, and resource injection attacks. The root cause stems from insufficient input validation and output encoding in the ISE and ISE-PIC components. These flaws are exploitable over the network without requiring authentication or user interaction, with the impact scoped to the confidentiality, integrity, and availability of the entire system and connected infrastructure. Cisco has released patched versions for all supported release branches, with no workarounds available; immediate patching is required for affected deployments.
Affected products
- Cisco Identity Services Engine 3.0 and earlier, 3.1 before 3.1 Patch 12, 3.2 before 3.2 Patch 11, 3.3 before 3.3 Patch 12, 3.4 before 3.4 Patch 7, 3.5 before 3.5 Patch 4
- Cisco Identity Services Engine Passive Identity Connector 3.4 and earlier
Timeline
- 2026-09-16: disclosed
- exploited: One related vulnerability is known to be actively exploited
- 2026-09-16: patched: Fixed releases available for all supported versions