Wednesday , August 19 2026
Cisco ISE

Critical Cisco ISE Vulnerability Enables Remote Code Execution

Cisco has revealed critical security flaws in its Identity Services Engine (ISE). These flaws could let attackers run harmful code from afar and get sensitive information, which is a big risk for business networks.

The flaw, noted as CVE-2026-20181 and CVE-2026-20190, were shared in advisory ID cisco-sa-ise-multi-G5WP8vv on June 17, 2026.

Critical WordPress Plugin Flaw Exposes 600,000 Sites to Attacks

A big security flaw in the Forminator Forms WordPress plugin might let unapproved users upload harmful PHP files. This could...
Read More
Critical WordPress Plugin Flaw Exposes 600,000 Sites to Attacks

Apple Patches 28 Security Flaws in macOS, iOS, and iPadOS

Apple has put out security updates for macOS, iOS, and iPadOS. These updates fix 28 problems that could let users...
Read More
Apple Patches 28 Security Flaws in macOS, iOS, and iPadOS

DoNot (APT-C-35) Targeting Bangladesh Military Personnel

Bangladesh's military and defense system is actively under targeted attack linked to DoNot Team, or APT-C-35, as stated in a...
Read More
DoNot (APT-C-35) Targeting Bangladesh Military Personnel

McDonald’s, Vodafone Affected by Azure Theft Campaign Exposing Millions of Records

A large Azure data theft campaign is surfacing on the dark web. A hacker is offering employee lists taken from...
Read More
McDonald’s, Vodafone Affected by Azure Theft Campaign Exposing Millions of Records

NIST to Modernize NVD in the Age of Artificial Intelligence

National Institute of Standards and Technology (NIST) demands feedback from industry and the government on how to update the National...
Read More
NIST to Modernize NVD in the Age of Artificial Intelligence

ALERT
Multiple TP-Link Flaws Allow to Bypass Auth and Escalate Privileges

TP-Link has revealed several serious security flaws in Aginet networking products managed by ISPs. This includes mesh systems, routers, PON...
Read More
ALERT  Multiple TP-Link Flaws Allow to Bypass Auth and Escalate Privileges

LiteLLM supply chain attack reveals 153GB of stolen credentials online

153GB record surface online stolen during the LiteLLM supply chain attack linked to thousands of corporate domains, including AWS, Samsung,...
Read More
LiteLLM supply chain attack reveals 153GB of stolen credentials online

PATCHCORD Backdoor Targets Telecom and CII In South Asia

A previously undocumented backdoor called PATCHCORD actively target telecom and critical information infrastructure (CII) in South Asia. According to Acronis...
Read More
PATCHCORD Backdoor Targets Telecom and CII In South Asia

Fortinet Fixes Multiple Flaws in FortiWeb, FortiManager, and FortiClient

Fortinet has released fixes for a set of authentication flaws in its FortiWeb, FortiManager, and FortiClient products. It warns admins...
Read More
Fortinet Fixes Multiple Flaws in FortiWeb, FortiManager, and FortiClient

“City-Forum” Campaign
“City-Forum” Campaign Attacks Salesforce and ServiceNow Instances Worldwide

A data theft plan is stealing information from anonymous users on Salesforce Experience Cloud and ServiceNow customer portals using special...
Read More
“City-Forum” Campaign  “City-Forum” Campaign Attacks Salesforce and ServiceNow Instances Worldwide

The flaws affect Cisco ISE and ISE Passive Identity Connector (ISE-PIC) setups, no matter how they are set up, and have a CVSS score of 9.1. The biggest flaw, CVE-2026-20181, is a remote code execution (RCE) weakness that happens because user input is not checked properly.

Cisco ISE RCE Vulnerability

Successful attacks let hackers run any commands on the operating system. They might first get user access and then increase their permissions to root, taking full control of the device.

In single-node setups, an attack can cause a denial-of-service. This stops new endpoints from connecting to the network until the system is fixed. This could trouble business access control systems that depend on Cisco ISE.

The second flaw, CVE-2026-20190, is a risk of information being revealed due to bad authorization checks. Unlike the RCE issue, this risk can be used by a remote attacker who is not logged in.

Attackers can send specially made requests to get sensitive information saved on the device, like hashed login details. They could use these details in more attacks, raising the risk of moving around the network.

Cisco said that all versions of ISE and ISE-PIC are impacted, but the exact flaws differ by version.

Cisco has provided fixes for the flaws in ISE 3.3 Patch 11 and ISE 3.4 Patch 6. A fix for ISE 3.5 Patch 4 is expected in August 2026. Earlier versions need to be updated to supported releases, and there are no workarounds. Therefore, patching is the only real solution.

Cisco’s Product Security Incident Response Team (PSIRT) said there is no proof of active attacks right now. But since it’s very serious and easy to exploit, businesses should focus on updates.

New Rokarolla Android malware hits 217 banking and crypto apps

Check Also

PATCHCORD

PATCHCORD Backdoor Targets Telecom and CII In South Asia

A previously undocumented backdoor called PATCHCORD actively target telecom and critical information infrastructure (CII) in …