CVE-2026-20130
Cisco Identity Services Engine Hardening Release - Improper Neutralization Vulnerabilities
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20130 are related to improper neutralization of special elements issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.
In plain language
AI Act nowThis is a critical flaw in Cisco Identity Services Engine software that may let an outsider take over affected systems, so small businesses using it should act now.
Network-reachable, unauthenticated improper neutralization of special elements (CWE-74) in Cisco Identity Services Engine Software and Cisco ISE Passive Identity Connector, with public exploit availability and critical CVSS 10.0 impact.
What to do now
- Check whether your organization runs Cisco Identity Services Engine software or its Passive Identity Connector.
- Ask your Cisco support contact whether your installed release is affected by CVE-2026-20130; Cisco has not published fixed-version information.
- Limit access to the affected systems to only necessary administrators and networks until Cisco provides remediation.
- Watch Cisco security advisories for a fixed release and install it as soon as Cisco confirms one.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20130 and every CVE in our database. Create a free account — no credit card required.
Create Free Account