Remote Code Execution Vulnerability in Cisco Identity Services Engine
CVE-2026-20180

9.9CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
15 April 2026

Badges

👾 Exploit Exists

What is CVE-2026-20180?

A vulnerability in Cisco Identity Services Engine (ISE) permits authenticated, remote attackers to execute arbitrary commands on the operating system of affected devices. This flaw arises from insufficient validation of user-supplied input. By sending a specially crafted HTTP request to the vulnerable system, an attacker with Read Only Admin credentials can gain user-level access and potentially escalate their privileges to root. In single-node ISE deployments, such exploitation may render the node unavailable, leading to a denial of service (DoS) condition, preventing unauthenticated endpoints from accessing the network until recovery.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.