
CISCO has released patches for a critical command execution vulnerability in its Identity Services Engine that lets authenticated administrators gain root access and could trigger denial‑of‑service conditions in single‑node deployments.
The flaw, tracked as CVE-2026-20181 and rated CVSS 9.1, stems from improper validation of user input in the administrative interface, allowing an attacker with valid admin credentials to execute arbitrary commands on the underlying operating system.
A second flaw, recorded as CVE-2026-20190 with a CVSS score of 7.5, permits unauthorized information disclosure from the same components and was addressed in the same updates.
Patches are available for ISE and ISE‑PIC versions 3.3 Patch 11, 3.4 Patch 6 and a hotfix for version 3.5.
Cisco says there is no evidence that either vulnerability has been exploited in the wild and no threat actors have been linked to the flaws, according to details in the SecurityAffairs report.
The update serves as a reminder that privileged administrative accounts remain a high‑value target, especially when they can be leveraged to execute commands with root privileges on network‑critical systems, as noted in the SecurityWeek coverage.
Administrators should update affected appliances to the patched versions, enforce multi‑factor authentication for admin interfaces, limit admin accounts to those that require them and review audit logs for any unexpected command execution.