Remote Code Execution Vulnerability in Cisco Identity Services Engine
CVE-2026-20180

9.9CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
15 April 2026

Badges

๐Ÿ‘พ Exploit Exists๐Ÿ“ฐ News Worthy

What is CVE-2026-20180?

A vulnerability in Cisco Identity Services Engine (ISE) permits authenticated, remote attackers to execute arbitrary commands on the operating system of affected devices. This flaw arises from insufficient validation of user-supplied input. By sending a specially crafted HTTP request to the vulnerable system, an attacker with Read Only Admin credentials can gain user-level access and potentially escalate their privileges to root. In single-node ISE deployments, such exploitation may render the node unavailable, leading to a denial of service (DoS) condition, preventing unauthenticated endpoints from accessing the network until recovery.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

News Articles

Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution

Cisco patches four CVEs up to CVSS 9.9 in ISE and Webex, preventing code execution and user impersonation risks.

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • ๐Ÿ“ฐ

    First article discovered by The Hacker News

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.