Cisco patches critical Cisco ISE and ISE-PIC command-execution flaw CVE-2026-20181

Cisco released security fixes for a critical flaw in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that could let an attacker run commands on affected systems. The bug, CVE-2026-20181, is a 9.1-severity input-validation issue that can be exploited over HTTP by a remote attacker with valid administrative credentials to gain OS-level access and then escalate to root; in single-node deployments it can also cause a denial-of-service. Fixes are in ISE/ISE-PIC 3.3 Patch 11 and 3.4 Patch 6, with a hotfix for 3.5 and inclusion planned for 3.5 Patch 4; Cisco also fixed CVE-2026-20190, an unauthenticated information-disclosure flaw.
Why it matters: Organizations using Cisco ISE or ISE-PIC should patch quickly because these systems help control who and what can join the network, making compromise especially sensitive. Even though Cisco says it has no evidence of active exploitation, the combination of root-level impact and possible credential exposure makes this an update-now issue for administrators.

Sources

Critical Command Execution Vulnerability Patched in Cisco ISE
Ionut Arghire 2026.06.18 100% relevant
This article appears to be the first tracked item here focused on Cisco's disclosure and patching of CVE-2026-20181 in ISE/ISE-PIC, with the core technical details and fixed versions.
← Back to all stories