{"id":175545,"date":"2026-01-08T05:44:00","date_gmt":"2026-01-08T10:44:00","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/01\/08\/cisco-patches-ise-security-vulnerability-after-public-poc-exploit-release\/"},"modified":"2026-01-08T05:50:09","modified_gmt":"2026-01-08T10:50:09","slug":"cisco-patches-ise-security-vulnerability-after-public-poc-exploit-release","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/01\/08\/cisco-patches-ise-security-vulnerability-after-public-poc-exploit-release\/","title":{"rendered":"Cisco Patches ISE Security Vulnerability After Public PoC Exploit Release"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/01\/cisco-patches-ise-security.html\">Cisco Patches ISE Security Vulnerability After Public PoC Exploit Release<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/01\/cisco-patches-ise-security.html\">https:\/\/thehackernews.com\/2026\/01\/cisco-patches-ise-security.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-01-08 05:44:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p>Author: <a href=\"\"><\/a><\/p>\n<p> Using an unordered list, summarize the following article with between 4 and 8 key points.<br \/>\n\ue802Jan 08, 2026\ue804Ravie LakshmananNetwork Security \/ Vulnerability<br \/>\nCisco has released updates to address a medium-severity security flaw in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) with a public proof-of-concept (PoC) exploit.<br \/>\nThe vulnerability, tracked as CVE-2026-20029 (CVSS score: 4.9), resides in the licensing feature and could allow an authenticated, remote attacker with administrative privileges to gain access to sensitive information.<br \/>\n&#8220;This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC,&#8221; Cisco said in a Wednesday advisory. &#8220;An attacker could exploit this vulnerability by uploading a malicious file to the application.&#8221;<br \/>\nSuccessful exploitation of the shortcoming could allow an attacker with valid administrative credentials to read arbitrary files from the underlying operating system, which the company said should be off-limits even to administrators.<\/p>\n<p>Bobby Gould of Trend Micro Zero Day Initiative has been credited with discovering and reporting the flaw. It affects the following versions &#8211;<\/p>\n<p>Cisco ISE or ISE-PIC Release earlier than 3.2 &#8211; Migrate to a fixed release<br \/>\nCisco ISE or ISE-PIC Release 3.2 &#8211; 3.2 Patch 8<br \/>\nCisco ISE or ISE-PIC Release 3.3 &#8211; 3.3 Patch 8<br \/>\nCisco ISE or ISE-PIC Release 3.4 &#8211; 3.4 Patch 4<br \/>\nCisco ISE or ISE-PIC Release 3.5 &#8211; Not vulnerable<\/p>\n<p>Cisco said there are no workarounds to address the flaw, adding it&#8217;s aware of the availability of a PoC exploit code. There are no indications that it has been exploited in the wild.<br \/>\nIn tandem, the networking equipment company also shipped fixes for two other medium-severity bugs stemming from the processing of Distributed Computing Environment Remote Procedure Call (DCE\/RPC) requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, impacting availability.<br \/>\nTrend Micro researcher Guy Lederfein has acknowledged for reporting the flaws. The details of the issues are as follows &#8211;<\/p>\n<p>CVE-2026-20026 (CVSS score: 5.8) &#8211; Snort 3 DCE\/RPC denial-of-service vulnerability<br \/>\nCVE-2026-20027 (CVSS score: 5.3) &#8211; Snort 3 DCE\/RPC information disclosure vulnerability<\/p>\n<p>They affect a number of Cisco products &#8211;<\/p>\n<p>Cisco Secure Firewall Threat Defense (FTD) Software, if Snort 3 was configured<br \/>\nCisco IOS XE Software<br \/>\nCisco Meraki software<\/p>\n<p>With vulnerabilities in Cisco products frequently targeted by bad actors, it&#8217;s crucial that users update to the latest version for adequate protection.<\/p>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cisco Patches ISE Security Vulnerability After Public PoC Exploit Release https:\/\/thehackernews.com\/2026\/01\/cisco-patches-ise-security.html Publish Date: 2026-01-08 05:44:00&#8230;<\/p>\n","protected":false},"author":1,"featured_media":175546,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjybuSkMzO3sPyC2aweCyQ7gBCiWeZ0MKZORj98gSkWfOtEBpzOFHt7hqNsdT1eqWpHyhQfiHHUw9U6sMvAI5Nj7JYfXd-BbxZYhV7AFPY6orjs-g0asPZceU4bBweF1odEupcmfSvxXx8Jsci1v8alq87jE0FJPaE6uYHy39KIBaoYd97VqDPQELznEpwJ\/s790-rw-e365\/cisco.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[31,27],"class_list":["post-175545","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-exploit","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/175545"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=175545"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/175545\/revisions"}],"predecessor-version":[{"id":175547,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/175545\/revisions\/175547"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/175546"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=175545"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=175545"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=175545"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}