• News/
  • https://www.theregister.com/2026/01/08/rcisco_ise_bug_poc/

Patch Cisco ISE bug now before attackers abuse proof-of-concept exploit

The Register
·
Jessica Lyons
·
Published Jan 8, 2026
·
Updated

Cisco patched a bug in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products that allows remote attackers with admin-level privileges to access sensitive information - and warned that a public, proof-of-concept exploit for the flaw exists online. ISE is Cisco's network access control and security policy platform, and companies use it to centrally manage and enforce security policies across users and devices. The bug, tracked as CVE-2026-20029, received a medium-severity 4.9 CVSS rating and it affects ISE and ISE-PIC, regardless of device configuration. It's due to improper parsing of XML processed by ISE and ISE-PIC's web-based management interface. "An attacker could exploit this vulnerability by uploading a malicious file to the application," according to the Wednesday security advisory. "A successful exploit could allow the attacker to read arbitrary files from the underlying operating system that could include sensitive data that should otherwise be inaccessible even to administrators." Cisco credited Trend Micro Zero Day Initiative's bug hunter Bobby Gould with spotting and reporting this vulnerability. "This vulnerability does require authentication, so that's the first barrier to exploitation," ZDI's Head of Threat Awareness Dustin Childs told The Register, adding that ZDI doesn't expect to see widespread abuse of this flaw given its high-privilege requirements. But, assuming that an attacker stole or otherwise obtained admin credenti...

Read full article

Affected Software

2 affected components
Cisco Identity Services Engine>=exactly 4.9
Cisco ISE Passive Identity Connector>=exactly 4.9
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a recently patched vulnerability in Cisco's Identity Services Engine (ISE) and ISE Passive Identity Connector that could allow remote attackers to access sensitive information.

2

What security implications are discussed in the article?

The security implications include the potential for remote attackers with admin-level privileges to exploit the vulnerability and gain unauthorized access to sensitive data.

3

What products or software are affected by the vulnerability?

The affected products are Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector, specifically version 4.9.

4

What steps should users take in light of this vulnerability?

Users are advised to patch the Cisco ISE and ISE Passive Identity Connector immediately to protect against potential exploitation.

5

Is there any proof-of-concept available for the vulnerability?

Yes, the article warns that there is a proof-of-concept exploit publicly available, increasing the urgency for users to apply the patch.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203