Junglewise Threat Intelligence

CVE-2026-20211: Cisco ISE remote code execution via unsafe Java deserialization

CVE-2026-20211 · Severity: critical · CVSS 9.1 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) is a network access and policy management platform used to authenticate and authorize users and devices on corporate networks. An authenticated attacker with high-privileged credentials can exploit unsafe Java object deserialization to execute arbitrary commands with root privileges, potentially taking ISE offline and blocking all unauthenticated endpoints from network access.

Technical details

This vulnerability stems from insecure deserialization of Java objects in Cisco ISE. An authenticated attacker with high-privileged administrative credentials can send a crafted serialized Java object to the affected device. The vulnerable component fails to properly validate or sanitize the deserialized object, allowing arbitrary code execution. A successful exploit grants user-level access to the underlying operating system, followed by privilege escalation to root. In single-node deployments, exploitation causes denial of service by rendering the ISE node unavailable, blocking network access for unauthenticated endpoints until recovery.

Affected products

  • Cisco Identity Services Engine

Timeline

  • 2026-09-16: disclosed

References

Related threats