Vulnerability in Identity Service Engine with exploit code patched by Cisco


  • CVE-2026-20029 in Cisco ISE/ISE-PIC allows arbitrary file reads via malicious XML uploads
  • Mining requires valid administrator credentials; no workaround exists: the fix is ​​the only fix
  • PoC exploit available; Past ISE Breaches Show Attackers Actively Targeting Corporate Network Access Controls

Cisco fixed a medium severity vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), for which there is a proof of concept (PoC) exploit.

In a security advisory published by Cisco, the networking giant said the bug was caused by incorrect parsing of XML processed by the web management interface of the affected tools.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top