Input Validation Weakness in Cisco Identity Services Engine and Passive Identity Connector
CVE-2026-20237

9.1CRITICAL

Key Information:

Badges

👾 Exploit Exists

What is CVE-2026-20237?

Cisco has identified vulnerabilities in its Identity Services Engine (ISE) and Passive Identity Connector (ISE-PIC). These vulnerabilities stem from improper input validation issues, compromising the security integrity of the affected products. This essential software hardening release addresses these weaknesses, ensuring enhanced protection against potential threats. Users are urged to update their systems to benefit from the latest security features and maintain robust protection.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.