Skip to content
VulniPulse
Highest advisory severityCritical 1 vendor · 1 advisory

CVE-2026-20186

CVE-2026-20186: 1 tracked advisory record across Cisco. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Cisco

1 advisory
  • Advisory severityCritical9.9

    Critical [CVE-2026-20180 +1] Cisco Identity Services Engine Remote Code Execution Vulnerabilities

    cisco-sa-ise-rce-4fverepvSource published Source updated

    This bulletin covers 2 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have at least Read Only Admin credentials. These vulnerabilities are due to insufficient validation of user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node Cisco ISE deployments, successful exploitation of these vulnerabilities could cause the affected ISE node to become unavailable, resulting in a denial of…

    Related products — impact not confirmed
    • ISE
    • Identity Services Engine Software
    Source-reported affected versions
    • Scope: These vulnerabilities affect Cisco ISE, regardless of device configuration.
    • Earlier than 3.2 — Migrate to a fixed release
    • Release 3.2 (first fixed: 3.2 Patch 8)
    • Release 3.3 (first fixed: 3.3 Patch 8)

    1 more entries in the full advisory.

    Source-reported fixed versions
    • 3.2 Patch 8
    • 3.3 Patch 8
    • 3.4 Patch 4
    Mitigation guidance
    • Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
    • Earlier than 3.2: migrate to a fixed release.
    • Release 3.2: upgrade to 3.2 Patch 8.
    • Release 3.3: upgrade to 3.3 Patch 8.

    1 more entries in the full advisory.

    Workarounds
    • There are no workarounds that address these vulnerabilities.

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery