惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
博客园 - 司徒正美
博客园_首页
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
月光博客
月光博客
I
InfoQ
M
MIT News - Artificial intelligence
T
Tailwind CSS Blog
L
LangChain Blog
Last Week in AI
Last Week in AI
A
About on SuperTechFans
B
Blog
博客园 - 叶小钗
雷峰网
雷峰网
H
Help Net Security
WordPress大学
WordPress大学
大猫的无限游戏
大猫的无限游戏
博客园 - 【当耐特】
云风的 BLOG
云风的 BLOG
Microsoft Azure Blog
Microsoft Azure Blog
小众软件
小众软件
aimingoo的专栏
aimingoo的专栏
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Critical Cisco ISE Vulnerability Allows Attacker to Execu...
Abinaya · 2026-06-18 · via Cyber Security News

Cisco has disclosed critical security vulnerabilities in its Identity Services Engine (ISE) that could allow attackers to execute malicious code remotely and access sensitive data, posing a significant risk to enterprise networks.

The vulnerabilities, tracked as CVE-2026-20181 and CVE-2026-20190, were published under advisory ID cisco-sa-ise-multi-G5WP8vv on June 17, 2026.

With a CVSS score of 9.1, the flaws impact Cisco ISE and ISE Passive Identity Connector (ISE-PIC) deployments regardless of configuration.

The most severe issue, CVE-2026-20181, is a remote code execution (RCE) vulnerability caused by improper validation of user-supplied input.

An authenticated attacker with administrative privileges can exploit the flaw by sending a crafted HTTP request to the affected system.

Cisco ISE RCE Vulnerability

Successful exploitation allows attackers to execute arbitrary commands on the underlying operating system. Attackers may initially gain user-level access and then escalate their privileges to root, gaining full control of the device.

In single-node deployments, exploitation can also lead to a denial-of-service condition, preventing new endpoints from authenticating to the network until the system is restored. This could disrupt enterprise access control systems that rely on Cisco ISE.

The second flaw, CVE-2026-20190, is an information disclosure vulnerability caused by improper authorization checks. Unlike the RCE issue, this vulnerability can be exploited by an unauthenticated remote attacker.

By sending crafted requests, attackers may gain access to sensitive information stored on the device, including hashed credentials. These credentials could be leveraged in further attacks, increasing the risk of lateral movement within a network.

Cisco confirmed that all versions of ISE and ISE-PIC are affected, though specific vulnerabilities vary by release.

Cisco has released fixes for the vulnerabilities in ISE 3.3 Patch 11 and ISE 3.4 Patch 6, with a fix for ISE 3.5 Patch 4 planned for August 2026.

Earlier versions must be migrated to supported releases, and no workarounds are available, making patching the only effective mitigation.

Cisco’s Product Security Incident Response Team (PSIRT) stated that there is currently no evidence of active exploitation in the wild. However, given the high severity and ease of exploitation, organizations are strongly advised to prioritize updates.

The vulnerabilities were reported by security researchers from TrendAI, STAR Labs, and the Zero Day Initiative, highlighting coordinated industry efforts in responsible disclosure.

Organizations using Cisco ISE should immediately assess their exposure and upgrade to fixed software versions.

Additional defensive measures include: Restricting administrative access to trusted networks, Monitoring logs for suspicious HTTP requests, Reviewing authentication and privilege escalation activity.

These vulnerabilities underscore the critical role of identity infrastructure in enterprise security and the potential impact when such systems are compromised.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.