Known vulnerabilities in Cisco Identity Services Engine (ISE)
Vendor:
Cisco Systems, Inc
Software:
Cisco Identity Services Engine (ISE)
Software CPE:
cpe:2.3:a:cisco_systems:cisco_identity_services_engine:*:*:*:*:*:*:*:*
Website:
https://www.cisco.com
Total vulnerabilities:
173
Public exploits:
4
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
3.5 Patch 4
3.3 Patch 5
3.2 Patch 8
3.5 Patch 3
3.4 Patch 6
3.3 Patch 11
3.2 Patch 10
3.1 Patch 11
3.5
3.3 Patch 8
3.4 Patch 4
3.3 Patch 7
3.2 P8
3.3 Patch 6
3.4 Patch 2
003.001(000.518)
003.002(000.542)
003.003(000.430)
003.004(000.608)
3.3 P3
3.2 P7
3.1 P10
3.3P5
3.2P6
3.2P4
3.1p10
3.1p2
3.4P1
3.3P4
3.2P7
3.4
3.3P2
3.1P9
3.3P3
3.2P5
3.3P1
3.1P8
3.3
3.2P3
3.1p7
3.0p8
2.7p10
3.2P2
3.0.0.458-Patch7
3.2.0.542 Patch1
3.1p6
2.6P12
3.1P4
3.0P7
3.2P1
3.1P5
3.2
3.0P6
2.7P8
2.7.0.305
2.6.0.156P5
2.4.0.357P11
3.1P3
2.7 Patch 7
3.1P1
3.0 Patch 5
2.7 Patch 6
2.6 Patch 11
3.0 Patch 4
2.7 Patch 5
2.6 Patch 10
2.2 Patch 15
2.2 Patch 14
2.2 Patch 13
2.2 Patch 12
2.2 Patch 11
2.2 Patch 10
2.2 Patch 9
2.2 Patch 8
2.2 Patch 7
2.2 Patch 6
2.2 Patch 5
2.2 Patch 4
2.2 Patch 3
2.2 Patch 2
2.2 Patch 1
3.0 Patch 3
3.1
2.7 Patch 4
3.0P2
2.7P3
2.6 Patch 9
2.4 Patch 14
3.0 Patch 1
2.7 Patch 2
2.7 Patch 1
2.6 Patch 8
2.6 Patch 6
2.6 Patch 5
2.6 Patch 4
2.4 Patch 13
2.4 Patch 12
2.4 Patch 11
2.4 Patch 9
2.4 Patch 8
2.4 Patch 7
2.4 Patch 6
2.4 Patch 5
2.4 Patch 4
2.4 Patch 3
2.4 Patch 2
2.4 Patch 1
2.3 Patch 5
2.3 Patch 4
2.3 Patch 3
2.3 Patch 2
2.3 Patch 1
2.6(0.905)
3.0
3.0(0.458)
3.0(0.395)
2.7(0.356)
2.6
2.5
2.4
2.3
2.3p7
2.4p12
2.6p7
2.4p13
2.2 Patch 17
2.4(0.911)
2.3(0.906)
2.6(0.902)
2.7p2
2.6(0.907)
2.4(0.913)
2.2(0.917)
2.6 Patch 7
2.7.0 FCS
2.6 Patch 2
2.6 Patch 1
2.2 Patch 16
2.7
2.6 Patch 3
2.3 Patch 6
2.3 Patch 7
2.4 Patch 10
2.5(0.225)
2.6.0
2.4.0 Patch 9
2.3(0.904)
2.6(0.156)
2.5(0.353)
2.4(0.901.1)
2.4(0.901)
2.2(0.911)
2.4(0.904)
2.5(0.1)
2.4(0.902)
2.4(0.903)
2.3(0.905)
2.2(0.913)
2.4(100.159)
2.2(0.910)
2.2(1.901)
2.4(0.183)
2.2(0.231)
2.1(0.188)
2.0(0.901)
2.1(0.905)
2.4(0.223)
2.4(0.357)
2.0(1.130)
2.0(0.306)
2.2(0.905)
2.4(0.192)
2.2(0.903)
2.0(0.249)
2.0(0.234)
2.1(102.103)
2.2(0.470)
2.4(0.247)
2.2(1.145)
2.1(0.474)
2.4(0.126)
2.3(0.298)
2.2(0.904)
2.2(0.471)
2.1(0.904)
2.1(0.229)
2.0.1
2.3(0.151)
2.2(0.283)
1.3(0.909)
2.1(102.101)
2.1(0.800)
2.2
2.1.0
2.0.0
1.4
1.2
1.1
1.3
Vulnerabilities (173)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU138321 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-20146 |
CWE-22 | Low | - | 17.07.2026 |
SB2026071781 |
||
| #VU134760 - Improper input validation CVE-2026-20181 |
CWE-20 | Low | 3.3 Patch 11, 3.4 Patch 6, 3.5 Patch 4 | 17.06.2026 |
SB2026061768 |
||
| #VU134761 - Improper Authorization CVE-2026-20190 |
CWE-285 | Medium | 3.4 Patch 6, 3.5 Patch 3 | 17.06.2026 |
SB2026061768 |
||
| #VU130288 - Observable Response Discrepancy CVE-2026-20195 |
CWE-204 | Medium | 3.3 Patch 11, 3.4 Patch 6, 3.5 Patch 3 | 07.05.2026 |
SB2026050720 |
||
| #VU130287 - Missing Authorization CVE-2026-20193 |
CWE-862 | Medium | 3.3 Patch 11, 3.4 Patch 6, 3.5 Patch 3 | 07.05.2026 |
SB2026050720 |
||
| #VU126401 - Improper Encoding or Escaping of Output CVE-2026-20136 |
CWE-116 | Low | 3.3 Patch 11, 3.4 Patch 6, 3.5 Patch 3 | 17.04.2026 |
SB2026041754 |
||
| #VU126400 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2026-20132 |
CWE-79 | Low | 3.2 Patch 8, 3.3 Patch 5, 3.4 Patch 2 | 17.04.2026 |
SB2026041752 |
||
| #VU126399 - Command injection CVE-2026-20186 |
CWE-77 | Medium | 3.2 Patch 8, 3.3 Patch 8, 3.4 Patch 4 | 17.04.2026 |
SB2026041751 |
||
| #VU126398 - Command injection CVE-2026-20180 |
CWE-77 | Medium | 3.2 Patch 8, 3.3 Patch 8, 3.4 Patch 4 | 17.04.2026 |
SB2026041751 |
||
| #VU126397 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-20148 |
CWE-22 | Low | 3.1 Patch 11, 3.2 Patch 10, 3.3 Patch 11, 3.4 Patch 6, 3.5 Patch 3 | 17.04.2026 |
SB2026041753 |
||
| #VU126396 - Command injection CVE-2026-20147 |
CWE-77 | Medium | 3.1 Patch 11, 3.2 Patch 10, 3.3 Patch 11, 3.4 Patch 6, 3.5 Patch 3 | 17.04.2026 |
SB2026041753 |
||
| #VU121600 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2026-20047 |
CWE-79 | Low | 3.2 P8, 3.3 Patch 8, 3.4 Patch 4 | 15.01.2026 |
SB2026011561 |
||
| #VU121599 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2026-20076 |
CWE-79 | Low | 3.2 P8, 3.3P5, 3.4P1 | 15.01.2026 |
SB2026011560 |
||
| #VU121071 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2026-20029 |
CWE-611 | Low | 3.2 P8, 3.3 Patch 8, 3.4 Patch 4 | 07.01.2026 |
SB2026010779 |
||
| #VU118128 - Incorrect Comparison CVE-2025-20343 |
CWE-697 | Medium | 3.4 Patch 4 | 05.11.2025 |
SB2025110529 |
||
| #VU118127 - Insufficient Granularity of Access Control CVE-2025-20305 |
CWE-1220 | Low | 3.4 Patch 4 | 05.11.2025 |
SB2025110528 |
||
| #VU118126 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-20304 |
CWE-79 | Low | 3.4 Patch 4 | 05.11.2025 |
SB2025110528 |
||
| #VU118125 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-20303 |
CWE-79 | Low | 3.4 Patch 4 | 05.11.2025 |
SB2025110528 |
||
| #VU118124 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-20289 |
CWE-79 | Low | 3.4 Patch 2 | 05.11.2025 |
SB2025110527 |
||
| #VU114317 - Improper Access Control CVE-2025-20131 |
CWE-284 | Low | 3.1 P10, 3.2 P7, 3.3 P3 | 21.08.2025 |
SB2025082112 |
Showing elements 1 - 20 out of 173