Threat actors have actively exploited a newly patched vulnerability in Cisco's Identity Services Engine (ISE) software since early July, weeks before the networking giant got around to issuing a fix. That's according to the Shadowserver Foundation, a nonprofit organization that scans and monitors the internet for exploitation. The company’s CEO, Piotr Kijewski, told The Register on Thursday that it had observed signs of exploitation "of what we believe is CVE-2025-20281 around July 5th." Kijewski added that the Shadowserver Foundation has observed a "few more exploitation attempts" since that time. The bug in question, rated 10 out of 10 on the CVSS scale, is a remote code execution flaw that lurks in the web-based management interface of Identity Services Engine (ISE), Cisco's network access control system. If successfully exploited, it allows unauthenticated attackers to execute arbitrary commands with root privileges on vulnerable devices. That's right: no login required, no special permissions – just instant admin-level access. Cisco first flagged the vulnerability in an advisory on June 25, along with CVE-2025-20337 – another 10-out-of-10-rated flaw that, like its sibling, allows miscreants to run arbitrary commands as root. This was followed by the disclosure of a third critical vulnerability that is also rated a perfect 10, CVE-2025-20282, on July 16. Cisco's advisory has been tweaked to confirm that "some of the bugs" are being actively exploited, though this revelati...
No login? No problem: Cisco ISE flaw gave root access before fix arrived, say researchers
The Register
·Carly Page
·Published Jul 24, 2025
·Updated
Affected Software
1 affected component
Cisco Identity Services Engine
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in Cisco's Identity Services Engine (ISE) that allowed unauthorized root access.
2
What security implications are discussed?
The vulnerability posed significant security risks as threat actors were able to exploit it actively before a patch was issued.
3
What products or software are affected?
The affected product is Cisco's Identity Services Engine (ISE) software.
4
When was the vulnerability actively exploited?
The vulnerability was actively exploited by attackers since early July, prior to the fix being released.
5
What actions were taken by Cisco in response to the vulnerability?
Cisco issued a patch for the vulnerability after it was exploited, addressing the security flaw in ISE.