Junglewise Threat Intelligence

CVE-2026-20237: Cisco Identity Services Engine improper input validation

CVE-2026-20237 · Severity: critical · CVSS 9.1 · Published 2026-09-16

Executive brief

Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), which are identity and access management platforms used for network authentication and device compliance, contain improper input validation vulnerabilities. An attacker on the network could exploit these flaws without authentication to compromise the confidentiality, integrity, and availability of the identity management system, potentially allowing unauthorized access to protected networks and customer data.

Technical details

The vulnerabilities are grouped under CWE-20 (Improper Input Validation) and related classes including CWE-74, CWE-284, CWE-522, CWE-669, and CWE-269. These issues were identified through Cisco's internal security review of the ISE and ISE-PIC engineering codebase. The vulnerabilities are network-reachable and require no authentication or user interaction to exploit (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C). At least one vulnerability in the CWE-284 (improper access control) category is known to be actively exploited in the wild. Cisco has released patched versions across all supported release branches (3.1 through 3.5), with patches identified in the Fixed Software section.

Affected products

  • Cisco Identity Services Engine 3.0 and earlier, 3.1 before 3.1 Patch 12, 3.2 before 3.2 Patch 11, 3.3 before 3.3 Patch 12, 3.4 before 3.4 Patch 7, 3.5 before 3.5 Patch 4
  • Cisco ISE Passive Identity Connector 3.4 and earlier

Timeline

  • 2026-09-16: disclosed: CVE-2026-20237 published as part of Cisco hardening release advisory
  • exploited: At least one vulnerability (CWE-284 improper access control) known to be actively exploited

References

Related threats