Arbitrary Command Execution Vulnerability in Cisco ISE Management Interface
CVE-2026-20307

9.9CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-20307?

A serious vulnerability exists in the web-based management interface of Cisco Identity Services Engine (ISE), allowing an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This issue stems from insecure deserialization of user-supplied Java byte streams. By sending a maliciously crafted serialized Java object to the management interface, an attacker could gain the ability to run arbitrary code on the device. In single-node setups, successful exploitation can make the impacted ISE node unavailable, resulting in denial of service (DoS) and preventing unauthenticated endpoints from accessing the network until restoration.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.