Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/cisco/identity-services-engine

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-20190 is a high-severity vulnerability in Cisco Identity Services Engine (ISE) Software versions 3.4.0 and 3.5.0. It allows an unauthenticated remote attacker to bypass authorization checks and view sensitive information, including hashed credentials, by sending crafted traffic to the affected device. This vulnerability does not impact integrity or availability but compromises confidentiality.

Join the discussion

CVE-2026-20147 is a critical command injection vulnerability in Cisco Identity Services Engine (ISE) software versions 3.1.0, 3.2.0, 3.3.0, 3.4.0, and 3.5.0. It allows an authenticated attacker with administrative credentials to execute arbitrary commands on the underlying operating system via crafted HTTP requests. Exploitation can lead to user-level access and privilege escalation to root. In single-node deployments, it may cause denial of service by making the ISE node unavailable, disrupting network access for unauthenticated endpoints.

Join the discussion

CVE-2026-20146 is a medium severity vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) versions 3.1.0 through 3.5.0. It allows an authenticated attacker with administrative privileges to perform path traversal attacks due to improper validation of user-supplied input. This can lead to reading or deletion of arbitrary files via crafted HTTP requests. No official patch or remediation details have been provided yet.

Join the discussion

A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This vulnerability is due to improper role-based access control (RBAC) permissions on the RADIUS Policy API endpoints. An attacker could exploit this vulnerability by bypassing the web-based management interface and directly calling an affected endpoint. A successful exploit could allow the attacker to gain unauthorized read access to sensitive RADIUS Policy details that are restricted for their role.

Join the discussion

A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device. This vulnerability exists because error messages are observed when the affected API endpoint is called. An attacker could exploit this vulnerability by sending a series of crafted requests to the affected endpoint and analyzing the differentiated responses. A successful exploit could allow the attacker to compile a list of valid usernames on an affected system.

Join the discussion

CVE-2026-20136 is a vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an authenticated local attacker with administrative privileges to perform command injection. This occurs due to insufficient validation of user-supplied input in a specific CLI command, enabling privilege escalation to root on the underlying operating system. The vulnerability affects multiple versions of Cisco ISE software up to 3.5 Patch 2 and has a CVSS score of 6. No official patch or remediation guidance has been provided yet. There are no known exploits in the wild at this time.

Join the discussion

CVE-2026-20180 is a critical vulnerability in Cisco Identity Services Engine (ISE) software that allows an authenticated remote attacker with at least Read Only Admin credentials to execute arbitrary commands on the underlying operating system. The vulnerability arises from insufficient validation of user-supplied input, enabling a crafted HTTP request to achieve user-level OS access and privilege escalation to root. In single-node deployments, exploitation can cause denial of service by making the ISE node unavailable, disrupting network access for unauthenticated endpoints.

Join the discussion

CVE-2026-20186 is a critical command injection vulnerability in Cisco Identity Services Engine (ISE) software. It allows an authenticated remote attacker with at least Read Only Admin credentials to execute arbitrary commands on the underlying operating system. Exploitation involves sending a crafted HTTP request that bypasses insufficient input validation. Successful attacks can lead to user-level access, privilege escalation to root, and in single-node deployments, denial of service by making the ISE node unavailable. This impacts network access for unauthenticated endpoints until recovery.

Join the discussion

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.

Join the discussion

A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to gain access to sensitive information.  This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the underlying operating system that could include sensitive data that should otherwise be inaccessible even to administrators. To exploit this vulnerability, the attacker must have valid administrative credentials.

Join the discussion

Showing 1 to 10 of 21 results

Filters:Package: pkg:github/cisco/identity-services-engine
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses