惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
J
Java Code Geeks
博客园 - 聂微东
量子位
C
Check Point Blog
T
The Blog of Author Tim Ferriss
T
Tailwind CSS Blog
G
Google Developers Blog
Google DeepMind News
Google DeepMind News
B
Blog
罗磊的独立博客
腾讯CDC
GbyAI
GbyAI
博客园 - 【当耐特】
A
About on SuperTechFans
M
MIT News - Artificial intelligence
U
Unit 42
D
Docker
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
小众软件
小众软件
S
SegmentFault 最新的问题
有赞技术团队
有赞技术团队

The Register - Security: Patches

Homeland security cybercops say patch TrueConf (Russia Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update Year-long Russian attacks infect users as soon as they look at an email Cisco SD-WAN make-me-root bug under attack Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 AI is making Patch Tuesday (kinda) fun again Anthropic to release Mythos-class models to the public Clear your calendar, Drupal user: You have a critically urgent patch to install Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Critical cPanel, WHM flaw probs exploited as 0-day, pros say Microsoft patch fell short. New Windows flaw exploited More Cisco SD-WAN bugs battered in attacks Critical Fortinet sandbox bugs allow auth bypass and RCE Ancient Excel bug comes out of retirement for active attacks Microsoft's massive Patch Tuesday: It's raining bugs Ransomware scum, other crims exploit 4 old Microsoft bugs Attackers exploited the FortiClient EMS bug as a 0-day Citrix NetScaler bug may be multiple flaws in one Ransomware crims abused Cisco 0-day weeks before disclosure Google rushes Chrome update to fix zero-days under attack CISA warns max-severity n8n bug is being exploited in the wild Cisco warns of two more SD-WAN bugs under active attack LexisNexis Legal & Professional confirms data breach Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover Patch these 4 critical, make-me-root SolarWinds bugs ASAP Attacker gets into France's DB listing all bank accounts CISA gives feds 3 days to patch actively exploited Dell bug CISA gives feds 3 days to patch actively exploited Dell bug Google fixes exploited Chrome CSS zero-day
Ruh-roh, there's a Cisco ISE bug POC on the loose
Jessica Lyons Jessica Lyons · 2026-01-09 · via The Register - Security: Patches

Patches

Patch Cisco ISE bug now before attackers abuse proof-of-concept exploit

No reports of active exploitation … yet

Cisco patched a bug in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products that allows remote attackers with admin-level privileges to access sensitive information - and warned that a public, proof-of-concept exploit for the flaw exists online.

ISE is Cisco's network access control and security policy platform, and companies use it to centrally manage and enforce security policies across users and devices.

The bug, tracked as CVE-2026-20029, received a medium-severity 4.9 CVSS rating and it affects ISE and ISE-PIC, regardless of device configuration. It's due to improper parsing of XML processed by ISE and ISE-PIC's web-based management interface.

"An attacker could exploit this vulnerability by uploading a malicious file to the application," according to the Wednesday security advisory. "A successful exploit could allow the attacker to read arbitrary files from the underlying operating system that could include sensitive data that should otherwise be inaccessible even to administrators."

Cisco credited Trend Micro Zero Day Initiative's bug hunter Bobby Gould with spotting and reporting this vulnerability.

"This vulnerability does require authentication, so that's the first barrier to exploitation," ZDI's Head of Threat Awareness Dustin Childs told The Register, adding that ZDI doesn't expect to see widespread abuse of this flaw given its high-privilege requirements.

But, assuming that an attacker stole or otherwise obtained admin credentials, they "could leak the contents of files on an affected system," Childs added.

The good news is that, as of now, Cisco and ZDI say they're not aware of any in-the-wild abuse of this CVE.

But considering the existence of a POC, which provides a blueprint on how to exploit the bug, we're guessing that CVE-2026-20029's exploitation status will soon change - so patch now.

It's unclear who published the POC, and Childs told us it wasn't ZDI. "We have not published PoC for this bug and have no plans to do so," he said. "We're not aware where the public PoC was published."

Companies should prioritize implementing this fix as networking devices are long-time favorites among government-backed attackers - and especially those from China - which means companies shouldn't leave these holes open for long.

In November, Amazon warned that an "advanced" attacker had exploited a max-severity ISE bug (CVE-2025-20337) as a zero-day to deploy custom malware. 

In July, researchers warned that miscreants had been exploiting another 10 out of 10 CVSS-rated ISE flaw (CVE-2025-20281), prompting Cisco to acknowledge in-the-wild activity and urge customers to patch.

The networking giant had originally disclosed CVE-2025-20281 in a June security advisory covering multiple max-severity flaws in the same ISE products, and later updated the bulletin as exploitation emerged. ®