CVE-2026-20237: Cisco Identity Services Engine Hardening Release - Input Validation Vulnerabilities
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20237 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.
Affected Software
Event History
Frequently Asked Questions
What access would an attacker need to exploit this issue?
The CVSS vector indicates that exploitation requires high privileges and can be performed over the network with low attack complexity. No user interaction is required.
What could successful exploitation affect?
The CVSS assessment rates confidentiality, integrity, and availability impact as high, with scope changed. The issue is rated critical with a 9.1 severity score.