CVE-2026-20130: pre-auth remote code execution in Cisco Cisco Identity Services Engine Software

An unauthenticated network attacker can execute arbitrary code and take full control of Cisco Identity Services Engine Software; tracked as CVE-2026-20130. The flaw stems from improper neutralization of special elements (CWE-74) and affects Cisco ISE 3.1.0, 3.1.0 p1 through p6, 3.2.0 and 3.2.0 p1–p2. An attacker only needs network access to a vulnerable ISE instance; no credentials or user interaction are required.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
10CRITICAL
EPSS
0.00395
CWE
CWE-74
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a remote, unauthenticated full‑compromise bug (CVSS 10.0) that can be triggered over the network, so immediately isolate vulnerable ISE instances from untrusted networks and apply Cisco guidance as a priority.

What is CVE-2026-20130?

An unauthenticated network attacker can execute arbitrary code and take full control of Cisco Identity Services Engine Software; tracked as CVE-2026-20130. The flaw stems from improper neutralization of special elements (CWE-74) and affects Cisco ISE 3.1.0, 3.1.0 p1 through p6, 3.2.0 and 3.2.0 p1–p2. An attacker only needs network access to a vulnerable ISE instance; no credentials or user interaction are required.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Cisco Cisco Identity Services Engine Software are affected?

BRANCHAFFECTEDFIXED
Cisco Identity Services Engine Software 3.x3.1.0
Cisco Identity Services Engine Software 3.x3.1.0 p1
Cisco Identity Services Engine Software 3.x3.1.0 p3
Cisco Identity Services Engine Software 3.x3.1.0 p2
Cisco Identity Services Engine Software 3.x3.2.0
Cisco Identity Services Engine Software 3.x3.1.0 p4
Cisco Identity Services Engine Software 3.x3.1.0 p5
Cisco Identity Services Engine Software 3.x3.2.0 p1
Cisco Identity Services Engine Software 3.x3.1.0 p6
Cisco Identity Services Engine Software 3.x3.2.0 p2

Is CVE-2026-20130 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-20130

  1. Restrict network exposure of Cisco Identity Services Engine; block access from untrusted networks and the internet.
  2. Follow Cisco’s vendor guidance and advisories for this vulnerability and any temporary workarounds.
  3. Monitor ISE logs and network traffic for signs of unauthorized access or anomalous commands.
  4. Plan to apply vendor fixes or upgrades once Cisco releases patched versions; consider isolating or replacing affected appliances until patched.

Frequently asked questions

Is CVE-2026-20130 being actively exploited?

There are no public reports of active exploitation of CVE-2026-20130 as of 2026-09-30.

Which Cisco Identity Services Engine versions are affected by CVE-2026-20130?

Cisco Identity Services Engine 3.1.0, 3.1.0 p1 through p6, 3.2.0, and 3.2.0 p1–p2 are listed as affected.

Is there a patch for CVE-2026-20130?

No fixed versions are listed in the provided facts; administrators should follow Cisco advisories for forthcoming patches and apply vendor guidance.

Does CVE-2026-20130 require authentication?

No; the vulnerability can be exploited remotely without authentication against Cisco Identity Services Engine.

References