More

    Vulnerability in Identity Service Engine with exploit code patched by Cisco



    • CVE-2026-20029 in Cisco ISE/ISE-PIC allows arbitrary file reads via malicious XML uploads
    • Exploitation requires valid admin credentials; no workarounds exist—patching is the only fix
    • PoC exploit available; past ISE flaws show attackers actively target enterprise network access controls

    Cisco has patched a medium-severity vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), for which there is a proof-of-concept (PoC) exploit.

    In a security advisory published by Cisco, the network giant said the bug was due to improper parsing of XML that is processed by the web-based management interface of the affected tools.


    https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-2560-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img