Cisco patched a bug in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products that allows remote attackers with admin-level privileges to access sensitive information - and warned that a public, proof-of-concept exploit for the flaw exists online. ISE is Cisco's network access control and security policy platform, and companies use it to centrally manage and enforce security policies across users and devices. The bug, tracked as CVE-2026-20029, received a medium-severity 4.9 CVSS rating and it affects ISE and ISE-PIC, regardless of device configuration. It's due to improper parsing of XML processed by ISE and ISE-PIC's web-based management interface. "An attacker could exploit this vulnerability by uploading a malicious file to the application," according to the Wednesday security advisory. "A successful exploit could allow the attacker to read arbitrary files from the underlying operating system that could include sensitive data that should otherwise be inaccessible even to administrators." Cisco credited Trend Micro Zero Day Initiative's bug hunter Bobby Gould with spotting and reporting this vulnerability. "This vulnerability does require authentication, so that's the first barrier to exploitation," ZDI's Head of Threat Awareness Dustin Childs told The Register, adding that ZDI doesn't expect to see widespread abuse of this flaw given its high-privilege requirements. But, assuming that an attacker stole or otherwise obtained admin credenti...
Patch Cisco ISE bug now before attackers abuse proof-of-concept exploit
Affected Software
Frequently Asked Questions
What is the main topic of this article?
The article discusses a recently patched vulnerability in Cisco's Identity Services Engine (ISE) and ISE Passive Identity Connector that could allow remote attackers to access sensitive information.
What security implications are discussed in the article?
The security implications include the potential for remote attackers with admin-level privileges to exploit the vulnerability and gain unauthorized access to sensitive data.
What products or software are affected by the vulnerability?
The affected products are Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector, specifically version 4.9.
What steps should users take in light of this vulnerability?
Users are advised to patch the Cisco ISE and ISE Passive Identity Connector immediately to protect against potential exploitation.
Is there any proof-of-concept available for the vulnerability?
Yes, the article warns that there is a proof-of-concept exploit publicly available, increasing the urgency for users to apply the patch.