惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网
B
Blog
月光博客
月光博客
博客园 - 【当耐特】
WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
I
InfoQ
The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
博客园 - Franky
MyScale Blog
MyScale Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
B
Blog RSS Feed
H
Help Net Security

The Register - Security: Patches

Homeland security cybercops say patch TrueConf (Russia Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update Year-long Russian attacks infect users as soon as they look at an email Cisco SD-WAN make-me-root bug under attack Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 AI is making Patch Tuesday (kinda) fun again Anthropic to release Mythos-class models to the public Clear your calendar, Drupal user: You have a critically urgent patch to install Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Critical cPanel, WHM flaw probs exploited as 0-day, pros say Microsoft patch fell short. New Windows flaw exploited More Cisco SD-WAN bugs battered in attacks Critical Fortinet sandbox bugs allow auth bypass and RCE Ancient Excel bug comes out of retirement for active attacks Microsoft's massive Patch Tuesday: It's raining bugs Ransomware scum, other crims exploit 4 old Microsoft bugs Attackers exploited the FortiClient EMS bug as a 0-day Citrix NetScaler bug may be multiple flaws in one Ransomware crims abused Cisco 0-day weeks before disclosure Google rushes Chrome update to fix zero-days under attack CISA warns max-severity n8n bug is being exploited in the wild Cisco warns of two more SD-WAN bugs under active attack LexisNexis Legal & Professional confirms data breach Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover Patch these 4 critical, make-me-root SolarWinds bugs ASAP Attacker gets into France's DB listing all bank accounts CISA gives feds 3 days to patch actively exploited Dell bug CISA gives feds 3 days to patch actively exploited Dell bug Google fixes exploited Chrome CSS zero-day
Ruh-roh, there's a Cisco ISE bug POC on the loose
2026-01-09 · via The Register - Security: Patches

Patches

Patch Cisco ISE bug now before attackers abuse proof-of-concept exploit

No reports of active exploitation … yet

Cisco patched a bug in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products that allows remote attackers with admin-level privileges to access sensitive information - and warned that a public, proof-of-concept exploit for the flaw exists online.

ISE is Cisco's network access control and security policy platform, and companies use it to centrally manage and enforce security policies across users and devices.

The bug, tracked as CVE-2026-20029, received a medium-severity 4.9 CVSS rating and it affects ISE and ISE-PIC, regardless of device configuration. It's due to improper parsing of XML processed by ISE and ISE-PIC's web-based management interface.

REG AD

"An attacker could exploit this vulnerability by uploading a malicious file to the application," according to the Wednesday security advisory. "A successful exploit could allow the attacker to read arbitrary files from the underlying operating system that could include sensitive data that should otherwise be inaccessible even to administrators."

REG AD

Cisco credited Trend Micro Zero Day Initiative's bug hunter Bobby Gould with spotting and reporting this vulnerability.

"This vulnerability does require authentication, so that's the first barrier to exploitation," ZDI's Head of Threat Awareness Dustin Childs told The Register, adding that ZDI doesn't expect to see widespread abuse of this flaw given its high-privilege requirements.

But, assuming that an attacker stole or otherwise obtained admin credentials, they "could leak the contents of files on an affected system," Childs added.

The good news is that, as of now, Cisco and ZDI say they're not aware of any in-the-wild abuse of this CVE.

But considering the existence of a POC, which provides a blueprint on how to exploit the bug, we're guessing that CVE-2026-20029's exploitation status will soon change - so patch now.

It's unclear who published the POC, and Childs told us it wasn't ZDI. "We have not published PoC for this bug and have no plans to do so," he said. "We're not aware where the public PoC was published."

Companies should prioritize implementing this fix as networking devices are long-time favorites among government-backed attackers - and especially those from China - which means companies shouldn't leave these holes open for long.

In November, Amazon warned that an "advanced" attacker had exploited a max-severity ISE bug (CVE-2025-20337) as a zero-day to deploy custom malware. 

REG AD

In July, researchers warned that miscreants had been exploiting another 10 out of 10 CVSS-rated ISE flaw (CVE-2025-20281), prompting Cisco to acknowledge in-the-wild activity and urge customers to patch.

The networking giant had originally disclosed CVE-2025-20281 in a June security advisory covering multiple max-severity flaws in the same ISE products, and later updated the bulletin as exploitation emerged. ®