Friday , June 19 2026
Cisco ISE

Critical Cisco ISE Vulnerability Enables Remote Code Execution

Cisco has revealed critical security flaws in its Identity Services Engine (ISE). These flaws could let attackers run harmful code from afar and get sensitive information, which is a big risk for business networks.

The flaw, noted as CVE-2026-20181 and CVE-2026-20190, were shared in advisory ID cisco-sa-ise-multi-G5WP8vv on June 17, 2026.

Critical Cisco ISE Vulnerability Enables Remote Code Execution

Cisco has revealed critical security flaws in its Identity Services Engine (ISE). These flaws could let attackers run harmful code...
Read More
Critical Cisco ISE Vulnerability Enables Remote Code Execution

F5 Patches NGINX Flaw for Code Execution and DoS Attacks

F5 has shared a security warning about serious flaws in NGINX. These issues could let attackers run any code and...
Read More
F5 Patches NGINX Flaw for Code Execution and DoS Attacks

FortiBleed: 70,000 Fortinet Firewalls Compromised Globally

A vast cyber spying operation called “FortiBleed” has quietly compromised more than 73,932 different Fortinet firewall URLs in 194 countries....
Read More
FortiBleed: 70,000 Fortinet Firewalls Compromised Globally

New Rokarolla Android malware hits 217 banking and crypto apps

A new Android banking trojan called Rokarolla is hitting 217 banking and cryptocurrency apps with a wide range of 137...
Read More
New Rokarolla Android malware hits 217 banking and crypto apps

Phishing Campaign Exploits Legitimate Microsoft Login Flow

Attackers are using Microsoft’s OAuth 2.0 Device Authorization Grant (device code) flow in a campaign to take control of Microsoft...
Read More
Phishing Campaign Exploits Legitimate Microsoft Login Flow

ALERT
Cisco SD-WAN Zero-Day, FortiSandbox and cPanel flaws exploited in attacks

Cisco on Monday told customers about a new SD-WAN product flaw used in attacks. The flaw, called CVE-2026-20262, is a...
Read More
ALERT  Cisco SD-WAN Zero-Day, FortiSandbox and cPanel flaws exploited in attacks

“Panthalassa” builds floating AI data centers powered by ocean waves

Every American data center story these days follows almost the same pattern. Someone has the chips, someone has the cash,...
Read More
“Panthalassa” builds floating AI data centers powered by ocean waves

Critical Wazuh Vuln Enables Alert Tampering and Evidence Deletion

A critical security flaw has affected the open-source security community. Recently, complete details and working exploit code were shared online....
Read More
Critical Wazuh Vuln Enables Alert Tampering and Evidence Deletion

CVE-2026-0257
Palo Alto Warns of GlobalProtect VPN Vuln Actively Exploited

Palo Alto Networks Unit 42 has given an urgent alert about the active use of CVE-2026-0257. This is a serious...
Read More
CVE-2026-0257  Palo Alto Warns of GlobalProtect VPN Vuln Actively Exploited

BD Gov.t to set up Tk192.66cr AI hub with support from Koica

Bangladesh plans to spend Tk192.66 crore to make a national hub for artificial intelligence (AI) to train new AI experts....
Read More
BD Gov.t to set up Tk192.66cr AI hub with support from Koica

The flaws affect Cisco ISE and ISE Passive Identity Connector (ISE-PIC) setups, no matter how they are set up, and have a CVSS score of 9.1. The biggest flaw, CVE-2026-20181, is a remote code execution (RCE) weakness that happens because user input is not checked properly.

Cisco ISE RCE Vulnerability

Successful attacks let hackers run any commands on the operating system. They might first get user access and then increase their permissions to root, taking full control of the device.

In single-node setups, an attack can cause a denial-of-service. This stops new endpoints from connecting to the network until the system is fixed. This could trouble business access control systems that depend on Cisco ISE.

The second flaw, CVE-2026-20190, is a risk of information being revealed due to bad authorization checks. Unlike the RCE issue, this risk can be used by a remote attacker who is not logged in.

Attackers can send specially made requests to get sensitive information saved on the device, like hashed login details. They could use these details in more attacks, raising the risk of moving around the network.

Cisco said that all versions of ISE and ISE-PIC are impacted, but the exact flaws differ by version.

Cisco has provided fixes for the flaws in ISE 3.3 Patch 11 and ISE 3.4 Patch 6. A fix for ISE 3.5 Patch 4 is expected in August 2026. Earlier versions need to be updated to supported releases, and there are no workarounds. Therefore, patching is the only real solution.

Cisco’s Product Security Incident Response Team (PSIRT) said there is no proof of active attacks right now. But since it’s very serious and easy to exploit, businesses should focus on updates.

New Rokarolla Android malware hits 217 banking and crypto apps

Check Also

Wazuh

Critical Wazuh Vuln Enables Alert Tampering and Evidence Deletion

A critical security flaw has affected the open-source security community. Recently, complete details and working …