【Vulnerability Alert】High-Risk Security Vulnerabilities in Cisco ISE and ISE-PIC (CVE-2026-20130, CVE-2026-20192, CVE-2026- 20307, CVE-2026-76423 and CVE-2026-76460), Please Verify and Patch Promptly
Subject:【Vulnerability Alert】High-Risk Security Vulnerabilities in Cisco ISE and ISE-PIC (CVE-2026-20130, CVE-2026-20192, CVE-2026- 20307, CVE-2026-76423 and CVE-2026-76460), Please Verify and Patch Promptly
Researchers have discovered multiple high-risk security vulnerabilities in Cisco ISE and ISE-PIC (CVE-2026-20130, CVE-2026-20192, CVE-2026-20307, CVE-2026-76423 and CVE-2026-76460), including code injection, improper access control, insecure deserialization and authentication bypass. CVE-2026-76460 has already been exploited by attackers. Please verify and patch promptly.
【CVE-2026-20130】 An unauthenticated remote attacker may execute arbitrary code on affected devices by inserting improperly handled special elements into the output passed to downstream components.
【CVE-2026-20192】 An unauthenticated remote attacker may bypass authentication and authorization restrictions, gaining unauthorized access to affected devices.
【CVE-2026-20307】 An authenticated remote attacker may execute arbitrary code on the underlying operating system by sending a specially crafted Java serialized object to the web management interface, and escalate privileges to root.
【CVE-2026-76423】 An unauthenticated remote attacker may read and modify ISE configuration and identity data with administrator privileges by sending specially crafted HTTP requests to the externally exposed REST API port.
【CVE-2026-76460】 An unauthenticated remote attacker may bypass the web management interface authentication by sending specially crafted requests to the vulnerable API endpoint, gaining unauthorized access to affected devices.
Affected Platforms:
Cisco ISE and ISE-PIC versions 3.1 to 3.5
Cisco ISE and ISE-PIC versions 3.0 (inclusive) and earlier (end of software maintenance)