CVE-2026-20237
Cisco Identity Services Engine Hardening Release - Input Validation Vulnerabilities
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20237 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.
In plain language
AI Act nowThis is a critical flaw in Cisco Identity Services Engine Software and Cisco ISE Passive Identity Connector; businesses using either should treat it as urgent, although a fix has not been published.
CVE-2026-20237 is a critical improper-input-validation vulnerability (CWE-20) in Cisco Identity Services Engine Software and Cisco ISE Passive Identity Connector that requires high privileges and can affect other security boundaries.
What to do now
- Confirm whether you run Cisco Identity Services Engine Software or Cisco ISE Passive Identity Connector, and identify the installed version.
- Ask your Cisco support contact or IT provider whether your version is affected; no fixed version has been published.
- Restrict and review high-level administrator access, including removing accounts that are no longer needed.
- Watch Cisco security advisories for the vendor's fix and install it once available.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20237 and every CVE in our database. Create a free account — no credit card required.
Create Free Account