【Vulnerability Alert】Three Critical Security Vulnerabilities Have Been Identined in Cisco Identity Services
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026041709042020 | Publication Time | 2026/04/17 09:43 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026/04/17 09:43 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Three Critical Security Vulnerabilities Have Been Identined in Cisco Identity Services |
|||
| [Content] Forwarded from TWCERTCC-200-202604-00000018 Cisco Identity Services Engine (ISE) is an identity-based security management platform that can collect information from networks and user devices, and enforce policies and make control decisions within the network infrastructure. Cisco recently issued a critical security vulnerability advisory. 【CVE-2026-20180, CVSS: 9.9 and CVE-2026-20186, CVSS: 9.9】 Both are remote code execution vulnerabilities that allow an authenticated remote attacker to execute arbitrary commands on the affected underlying operating system. Successful exploitation of these vulnerabilities requires that the attacker have at least read-only administrator privileges. 【CVE-2026-20147, CVSS: 9.9】 This vulnerability allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of an affected device. Successful exploitation of this vulnerability requires that the attacker possess valid administrator credentials. (Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
| [Affected Platform]
Cisco ISE versions up to and including 3.2 |
|||
| [Recommended Actions]
【CVE-2026-20180, CVE-2026-20186】 Cisco ISE 3.2 Patch 8, Cisco ISE 3.3 Patch 8, Cisco ISE 3.4 Patch 5 【CVE-2026-20147】 Cisco ISE or Cisco ISE-PIC 3.1 Patch 11, Cisco ISE or Cisco ISE-PIC 3.2 Patch 10, Cisco ISE or Cisco ISE-PIC 3.3 Patch 11, Cisco ISE or Cisco ISE-PIC 3.4 Patch 6, Cisco ISE or Cisco ISE-PIC 3.5 Patch 3 Note: Cisco ISE-PIC has reached end of sale, and version 3.4 is the last supported version. |
|||
| [Reference] https://www.twcert.org.tw/tw/cp-169-10849-9d3d6-1.html |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





