1 of 1
Story summary
- Cisco has fixed a medium-severity security flaw in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), identified as CVE-2026-20029.
- This vulnerability allows authenticated remote attackers with administrative privileges to read sensitive files by uploading malicious XML.
- Cisco stated that there are no workarounds, making patching essential for affected versions earlier than 3.2, with specific patches for versions 3.2, 3.3, and 3.4.
- Cisco also patched two additional medium-severity vulnerabilities in the Snort 3 Detection Engine.
- Users are advised to update their systems to prevent potential exploitation.
