Vulnerability threat dossier

CVE-2026-20284

CiscoCisco Identity Services Engine Software

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the underlying database for the affected device. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored. To exploit this vulnerability, the attacker must have valid administrative credentials, have the SXP service enabled, and have at least one SXP connection configured.

VTP deterministic threat20.6of 100 · CVSS excluded

VTP analyst assessment

Cisco ISE SXP REST API SQL injection

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence76%
Public exploitation · VTP factREPORTED

Assessment

CVE-2026-20284 affects Cisco Identity Services Engine's SXP REST API. An authenticated remote attacker can submit crafted API input to exploit insufficient validation and view or modify data. Public reporting records an exploitation claim, but the mapped assertion has unknown source independence. Prioritize remediation where authenticated users can reach this API.

Why it matters

  • Cisco ISE manages identity and access-policy functions, so unauthorized data changes could affect security administration.
  • The attack requires valid authentication, but remote REST API access creates an opportunity for compromised or malicious privileged accounts.
  • The CVSS vector indicates high confidentiality, integrity, and availability impact after exploitation.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The exploitation report is not independently corroborated in the mapped assertion.

The available sources also discuss CVE-2026-76460 and broader Cisco issues; they do not establish exploitation of CVE-2026-20284.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use Cisco ISE, identify instances exposing the SXP REST API to authenticated users and apply Cisco's remediation for CVE-2026-20284.

AI baseline history (4)
  1. BASELINE ASSESSED
    Cisco ISE SXP REST API SQL injectiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    CVE-specific impact cannot be establishedgpt-5.6-terra · low
  3. BASELINE ASSESSED
    Reported exploitation of a Cisco ISE vulnerabilitygpt-5.6-terra · low
  4. BASELINE ASSESSED
    Cisco ISE authenticated vulnerabilitygpt-5.6-terra · low
Technical severityCRITICALCVSS 9.1 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0033th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.00; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

CERT ADVISORYNew CERT advisory
VENDOR ADVISORYNew vendor advisory
VENDOR ADVISORYNew vendor advisory
03

Claim provenance

Evidence and source independence

6publications detected
6underlying evidence chains

2 primary sources · 0 dependent secondary reports · 3 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:5ab4a16c4265c0ebb0b4292c8f32fe1076ae8968af7609fef890b5f755efaee0ACTIVE
Evidence
04

Event history

Threat timeline

  1. 07:2017 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 00:0017 Sept
    CERT ADVISORY

    New CERT advisory

    CERT-FR published evidence linked to CVE-2026-20284.

  3. 16:0716 Sept
    VENDOR ADVISORY

    New vendor advisory

    Cisco Product Security Incident Response Team published evidence linked to CVE-2026-20284.

  4. 16:0016 Sept
    VENDOR ADVISORY

    New vendor advisory

    Cisco Product Security Incident Response Team published evidence linked to CVE-2026-20284.

05

Original publications

Source record

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution. The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek .

CVE-2026-20079CVE-2026-20282CVE-2026-20283CVE-2026-20284CVE-2026-20316CVE-2026-20332
Separate evidence group
Original

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]

CVE-2025-20337CVE-2026-20176CVE-2026-20211CVE-2026-20284CVE-2026-20307CVE-2026-76423CVE-2026-76460
Separate evidence group
Original

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker

CVE-2026-20130CVE-2026-20176CVE-2026-20192CVE-2026-20194CVE-2026-20211CVE-2026-20234CVE-2026-20237CVE-2026-20242CVE-2026-20282CVE-2026-20283CVE-2026-20284CVE-2026-20287CVE-2026-20305CVE-2026-20306CVE-2026-20307CVE-2026-20322CVE-2026-20324CVE-2026-20325CVE-2026-20326CVE-2026-20329CVE-2026-20330CVE-2026-20331CVE-2026-20332CVE-2026-20333CVE-2026-20334CVE-2026-20335CVE-2026-20336CVE-2026-20340CVE-2026-20341CVE-2026-20342CVE-2026-20343CVE-2026-20344CVE-2026-20353CVE-2026-20360CVE-2026-20361CVE-2026-76409CVE-2026-76412CVE-2026-76413CVE-2026-76420CVE-2026-76423CVE-2026-76424CVE-2026-76425CVE-2026-76426CVE-2026-76427CVE-2026-76428CVE-2026-76440CVE-2026-76441CVE-2026-76442CVE-2026-76443CVE-2026-76460CVE-2026-76461
Separate evidence group
Original

Multiples vulnérabilités dans les produits Cisco (17 septembre 2026)

De multiples vulnérabilités ont été découvertes dans les produits Cisco. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. Cisco indique que la vulnérabilité CVE-2026-76460 est...

CVE-2026-20130CVE-2026-20135CVE-2026-20154CVE-2026-20176CVE-2026-20192CVE-2026-20194CVE-2026-20211CVE-2026-20222CVE-2026-20234CVE-2026-20237CVE-2026-20242CVE-2026-20247CVE-2026-20249CVE-2026-20250CVE-2026-20282CVE-2026-20283CVE-2026-20284CVE-2026-20287CVE-2026-20295CVE-2026-20300CVE-2026-20305CVE-2026-20306CVE-2026-20307CVE-2026-20322CVE-2026-20323CVE-2026-20324CVE-2026-20325CVE-2026-20326CVE-2026-20329CVE-2026-20330CVE-2026-20331CVE-2026-20332CVE-2026-20333CVE-2026-20334CVE-2026-20335CVE-2026-20336CVE-2026-20340CVE-2026-20341CVE-2026-20342CVE-2026-20343CVE-2026-20344CVE-2026-20352CVE-2026-20360CVE-2026-20361CVE-2026-76409CVE-2026-76412CVE-2026-76413CVE-2026-76420CVE-2026-76423CVE-2026-76424CVE-2026-76425CVE-2026-76426CVE-2026-76427CVE-2026-76428CVE-2026-76460
Separate evidence group
Original

Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables.&nbsp; To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery . Cisco Identity Services Engine Title CVE ID SIR Base Score Cisco Identity Services Engine Hardening Release: September 2026 CVE-2026-20130 CVE-2026-20192 CVE-2026-20194 CVE-2026-20234 CVE-2026-20237 CVE-2026-20287 Critical 10.0 Cisco Identity Services Engine Vulnerabilities CVE-2026-76423 CVE-2026-76425 CVE-2026-76426 CVE-2026-76427 CVE-2026-76428 CVE-2026-76424 Critical 10.0 Cisco Identity Services Engine Authentication Bypass Vulnerability CVE-2026-76460 Critical 10.0 Cisco Identity Services Engine Remote Code Execution Vulnerabilities CVE-2026-20211 CVE-2026-20176 CVE-2026-20307 Critical 9.9 Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities CVE-2026-20282 CVE-2026-20283 CVE-2026-20284 Critical 9.1 Cisco Identity Services Engine Command Injection Vulnerabilities CVE-2026-20306 CVE-2026-20305 Critical 9.1 Cisco Identity Services Engine RADIUS Denial of Service Vulnerability CVE-2026-20352 High 8.6 Cisco Identity Services Engine SQL Injection Vulnerabilities CVE-2026-20247 CVE-2026-20300 High 7.5 Cisco Identity Services Engine Cross-Site Scripting Vulnerability</ &lt;br/&gt;Security Impact Rating: Informational

CVE-2026-20130CVE-2026-20176CVE-2026-20192CVE-2026-20194CVE-2026-20211CVE-2026-20234CVE-2026-20235CVE-2026-20237CVE-2026-20242CVE-2026-20247CVE-2026-20249CVE-2026-20282CVE-2026-20283CVE-2026-20284CVE-2026-20287CVE-2026-20300CVE-2026-20305CVE-2026-20306CVE-2026-20307CVE-2026-20309CVE-2026-20324CVE-2026-20352CVE-2026-76423CVE-2026-76424CVE-2026-76425CVE-2026-76426CVE-2026-76427CVE-2026-76428CVE-2026-76460
Separate evidence group
Original

Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct SQL injections, modify data, or execute arbitrary commands on the underlying operating system on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Note: For CVE-2026-20282 and CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the scores indicate. The reason is that it is easy to get to root from the achieved privilege level. Cisco has released software updates that address these vulnerabilities. There are workarounds that address one of these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories . In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026 . &lt;br/&gt;Security Impact Rating: Critical &lt;br/&gt;CVE: CVE-2026-20282,CVE-2026-20283,CVE-2026-20284

CVE-2026-20282CVE-2026-20283CVE-2026-20284
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score20.6vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction0.08 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency6 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-943
CPE records
0
Deterministic history records
12
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.