Denial of Service Vulnerability in Cisco Identity Services Engine RADIUS Feature
CVE-2026-20352

8.6HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-20352?

A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) enables an unauthenticated, remote attacker to induce a denial of service condition on the device. This issue arises from inadequate handling of specific RADIUS requests, allowing an attacker to send a specially crafted request that disrupts the availability of the ISE node. In scenarios where the ISE operates as a standalone deployment, authentication for endpoints that have not connected prior will be hindered, leaving them unable to access the network until the node is restored to normal operation.

Affected Version(s)

Cisco Identity Services Engine Software 3.2.0

Cisco Identity Services Engine Software 3.2.0 p1

Cisco Identity Services Engine Software 3.2.0 p2

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.