Cisco is warning that three recently patched critical remote code execution vulnerabilities in Cisco Identity Services Engine (ISE) are now being actively exploited in attacks. Although the vendor did not specify how they were being exploited and whether they were successful, applying the security updates as soon as possible is now critical. “In July 2025, the Cisco PSIRT became aware of attempted exploitation of some of these vulnerabilities in the wild,” reads the updated advisory. “Cisco continues to strongly recommend that customers upgrade to a fixed software release to remediate these vulnerabilities.” Cisco Identity Services Engine (ISE) is a platform that enables large organizations to control network access and enforce security policies. The maximum severity flaws were first disclosed by the vendor on June 25, 2025 (CVE-2025-20281 and CVE-2025-20282) and July 16, 2025 (CVE-2025-20337). Here’s a brief description of the flaws: CVE-2025-20281: Critical unauthenticated remote code execution vulnerability in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). An attacker can send crafted API requests to execute arbitrary commands as root on the underlying OS, without authentication. Fixed in ISE 3.3 Patch 7 and 3.4 Patch 2. CVE-2025-20282: Critical unauthenticated arbitrary file upload and execution vulnerability in Cisco ISE and ISE-PIC Release 3.4. Lack of file validation allows attackers to upload malicious files into privileged directo...
Cisco: Maximum-severity ISE RCE flaws now exploited in attacks
BleepingComputer
·Bill Toulas
·Published Jul 22, 2025
·Updated
Affected Software
1 affected component
Cisco Identity Services Engine
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of critical remote code execution vulnerabilities in Cisco Identity Services Engine (ISE).
2
What security implications are discussed?
The article highlights that these vulnerabilities can allow attackers to execute arbitrary code, posing significant risks to affected networks.
3
What products or software are affected?
The affected software mentioned in the article is Cisco Identity Services Engine (ISE).
4
What vulnerabilities are being exploited according to the article?
The article mentions three critical remote code execution vulnerabilities that have been recently patched.
5
What action has Cisco taken regarding these vulnerabilities?
Cisco has issued patches for the vulnerabilities but warns that they are now being actively exploited in the wild.