THREAT OPS › Threat News › Cisco Identity Services Engine Command Injection Vulnerabilities
Cisco Identity Services Engine Command Injection Vulnerabilities
<p>Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform command injection attacks on an affected device and execute arbitrary commands as the <em>root </em>user. To exploit these vulnerabilities, the attacker must have valid administrative credentials.</p> <p>For more inform
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-20305cve
- CVE-2026-20306cve