DIRAS TAKE
Urgent: this is a remote, unauthenticated flaw that can yield full system compromise (CVSS 10.0 with PR:N/UI:N). Immediately limit network exposure of ISE and prepare to apply vendor updates or mitigations as soon as Cisco publishes fixed software.
What is CVE-2026-20192?
An unauthenticated remote attacker can fully compromise Cisco Identity Services Engine Software, leading to complete confidentiality, integrity, and availability loss; this is tracked as CVE-2026-20192. Affected releases include 3.1.0 (and service packs p1 through p6) and 3.2.0 (including p1 and p2). The vulnerability requires only network access and does not require valid credentials or user interaction, per the published CVSS vector.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Cisco Cisco Identity Services Engine Software are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Cisco Identity Services Engine Software 3.x | 3.1.0 | |
| Cisco Identity Services Engine Software 3.x | 3.1.0 p1 | |
| Cisco Identity Services Engine Software 3.x | 3.1.0 p3 | |
| Cisco Identity Services Engine Software 3.x | 3.1.0 p2 | |
| Cisco Identity Services Engine Software 3.x | 3.2.0 | |
| Cisco Identity Services Engine Software 3.x | 3.1.0 p4 | |
| Cisco Identity Services Engine Software 3.x | 3.1.0 p5 | |
| Cisco Identity Services Engine Software 3.x | 3.2.0 p1 | |
| Cisco Identity Services Engine Software 3.x | 3.1.0 p6 | |
| Cisco Identity Services Engine Software 3.x | 3.2.0 p2 |
Is CVE-2026-20192 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-20192
- Isolate Cisco Identity Services Engine from untrusted networks and the internet; restrict access to management interfaces to trusted IPs.
- Apply network-level controls such as ACLs and VPN-only access for administrative functions to reduce exposure.
- Enable and closely monitor logging and alerting for anomalous activity on ISE systems.
- Follow Cisco guidance and plan to apply vendor updates or hardening fixes when they are published; contact Cisco support for interim mitigation recommendations.
Frequently asked questions
Is CVE-2026-20192 being actively exploited?
There are no public reports of exploitation of CVE-2026-20192 as of 2026-09-30.
Which Cisco Identity Services Engine Software versions are affected by CVE-2026-20192?
Cisco Identity Services Engine Software releases affected include 3.1.0 (and service packs p1 through p6) and 3.2.0 (including p1 and p2).
Is there a patch for CVE-2026-20192?
No fixed versions are listed in the available facts; follow Cisco guidance and apply updates or hardening fixes when Cisco publishes them.
Does CVE-2026-20192 require authentication?
No. The vulnerability does not require valid credentials or user interaction and can be exploited with network access only.
References
- nvd.nist.gov/vuln/detail/CVE-2026-20192
- cve.org/CVERecord?id=CVE-2026-20192
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026