• News/
  • https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-flaw-with-exploit-code/

Cisco warns of Identity Service Engine flaw with exploit code

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 8, 2026
·
Updated

Cisco has patched a vulnerability in its Identity Services Engine (ISE) network access control solution, with public proof-of-concept exploit code, that can be abused by attackers with admin privileges. Enterprise admins use Cisco ISE to manage endpoint, user, and device access to network resources while enforcing a zero-trust architecture. The security flaw (CVE-2026-20029) affects Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of device configuration, and remote attackers with high privileges can exploit it to access sensitive information on unpatched devices. "This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application," Cisco said. "A successful exploit could allow the attacker to read arbitrary files from the underlying operating system that could include sensitive data that should otherwise be inaccessible even to administrators. To exploit this vulnerability, the attacker must have valid administrative credentials." While the Cisco Product Security Incident Response Team (PSIRT) found no evidence of active exploitation, it did warn that a proof-of-concept (PoC) exploit is available online. Cisco considers "any workarounds and mitigations (if applicable) to be temporary solutions" and said that it "strongly recommends that customers upgrade to th...

Read full article

Affected Software

2 affected components
Cisco Identity Services Engine=1.0
Cisco ISE Passive Identity Connector=1.0
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a recently patched vulnerability in Cisco's Identity Services Engine (ISE) that has exploit code publicly available.

2

What security implications are discussed in the article?

The article highlights that the vulnerability can be exploited by attackers with admin privileges, potentially compromising network security.

3

What products are affected by the vulnerability mentioned?

The affected products include Cisco Identity Services Engine and Cisco ISE Passive Identity Connector.

4

How can enterprises protect themselves from this vulnerability?

Enterprises are advised to apply the latest security patches provided by Cisco to mitigate the risk.

5

Is there any proof-of-concept exploit code available for this vulnerability?

Yes, the article mentions that there is public proof-of-concept exploit code available for the identified flaw.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203