Description
A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials.

This vulnerability is due to insecure deserialization of Java objects by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A weakness in Cisco Identity Services Engine allows an authenticated remote attacker with high‑privileged administrative credentials to send a crafted serialized Java object, exploiting insecure deserialization (CWE‑502). Successful exploitation results in remote code execution on the underlying operating system, enabling the attacker to gain user‑level access and subsequently elevate privileges to root. The attacker can also cause a denial of service in single‑node deployments, rendering the ISE node unavailable until it is restored, which in turn blocks endpoints from authenticating to the network.

Affected Systems

Cisco Identity Services Engine Software is impacted. Specific product versions are not disclosed in the advisory, so any version of ISE may be vulnerable until a patched release is applied.

Risk and Exploitability

The CVSS score of 9.1 indicates high severity. The EPSS score of <1% signifies a low but nonzero likelihood of exploitation. The vulnerability is not yet listed in CISA's KEV catalog. Exploitation requires that the attacker be authenticated with high‑privilege credentials, then send a crafted payload to the vulnerable endpoint. Once compromise occurs, the attacker can execute arbitrary commands and elevate to root, leading to full system compromise.

Generated by OpenCVE AI on September 18, 2026 at 00:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Cisco ISE patch or upgrade to the most recent release that addresses insecure deserialization.
  • Restrict network access to the ISE node, allowing only trusted administrative components to reach the management interface.
  • Monitor authentication and audit logs for unusual activity that may indicate exploitation attempts.
  • Segment the ISE management network with firewall rules to limit exposure to untrusted networks.

Generated by OpenCVE AI on September 18, 2026 at 00:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Software

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This vulnerability is due to insecure deserialization of Java objects by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to&nbsp;root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
Title Cisco Identity Services Engine Remote Code Execution Vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-17T11:39:23.586Z

Reserved: 2025-10-08T11:59:15.398Z

Link: CVE-2026-20211

cve-icon Vulnrichment

Updated: 2026-09-17T11:31:59.704Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:22.200

Modified: 2026-09-17T12:17:25.350

Link: CVE-2026-20211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:44Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data