Cisco ISE: Critical security vulnerability despite required admin rights
Summary
Cisco has released security updates for Identity Services Engine, ISE Passive Identity Connector, Webex App, Umbrella Virtual Appliance, and Crosswork Network Controller. The most serious issue affects ISE and ISE-PIC and can lead to remote code execution and root compromise if an attacker already has admin rights. Cisco also fixed additional vulnerabilities that enable information disclosure, privilege escalation, open redirect attacks, and server-side template injection. Older ISE releases no longer receive patches, so affected customers must upgrade to a supported version. The incident creates immediate pressure for admins to review versions, apply updates, and validate exposure across Cisco environments.
Classifications
industries
No industries detected
applications
Business Intelligence
AskAI Classifications
Labels
SaaS
Enterprise Software
Collaboration Software
Linked Companies
Cisco
$1B+