A critical vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE-PIC, identified as CVE-2025-20337, has a CVSS score of 10, indicating its high severity.
According to Cisco’s advisory, this vulnerability arises from “insufficient validation of user-supplied input” in a specific API. This means that an unauthenticated, remote attacker can execute arbitrary code on the underlying operating system with root privileges—without needing any credentials.
By infosecbulletin
/ Saturday , August 8 2026
A group of almost 800 harmful packages was added to the npm registry in a new effort to spread malware...
Read More
By infosecbulletin
/ Saturday , August 8 2026
Google has launched Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update brings 41 security...
Read More
By infosecbulletin
/ Friday , August 7 2026
Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. The...
Read More
By infosecbulletin
/ Friday , August 7 2026
The ISACA Dhaka Chapter Election for 2026–2028 will take place on 8, August-2026. Most of the executive roles are likely...
Read More
By infosecbulletin
/ Thursday , August 6 2026
Cisco has put out an important update for Cisco IOS XE Software. This update fixes serious security holes that could...
Read More
By infosecbulletin
/ Thursday , August 6 2026
The Open Web Application Security Project (OWASP) has published the Top 10 for LLM Applications 2026. This guide focuses on...
Read More
By infosecbulletin
/ Wednesday , August 5 2026
Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume...
Read More
By infosecbulletin
/ Wednesday , August 5 2026
Bangladesh's National Cyber Security Agency (NCSA) has launched two cybersecurity initiatives: the Cyber Incident Reporting System (CIRS) and the National...
Read More
By infosecbulletin
/ Wednesday , August 5 2026
Cybersecurity Researcher Jeremiah Fowler uncovered and reported to Express VPN a publicly exposed database that was neither password-protected nor encrypted....
Read More
By infosecbulletin
/ Tuesday , August 4 2026
Thousands of data centers are in danger because of a 22-year-old problem in Baseboard Management Controller (BMC) processors, says the...
Read More
This flaw “could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root,” Cisco warns.
The vulnerability affects
Cisco ISE 3.3 (Fixed in Patch 7)
Cisco ISE 3.4 (Fixed in Patch 2)
Cisco ISE 3.2 and earlier versions are unaffected by this vulnerability, providing some relief to organizations with older systems. However, those using newer versions must patch immediately to prevent serious issues.
The vulnerability lets attackers take full control of an affected system. By sending a harmful API request, they can directly insert commands into the operating system and gain root access, ignoring all security measures.
“An attacker could exploit these vulnerabilities by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device,” the advisory explains.
This exploit could be used to penetrate internal networks, install malware, steal credentials, or disable access controls.
Cisco’s Product Security Incident Response Team (PSIRT) has released patches for supported versions. There are no current signs of exploitation, but system administrators should address this serious vulnerability right away.