Cisco ISE Cloud Deployments Exposed to Remote Access Risk

Red | Vulnerability Report
Download PDF

CVE-2025-20286 is a critical vulnerability in Cisco ISE cloud deployments (AWS, Azure, OCI) due to shared static credentials across instances of the same version. It allows unauthenticated remote attackers to access, modify, or disrupt systems. Only cloud-based Primary Admin Nodes are affected; on-prem setups are safe. A public proof-of-concept exploit exists, increasing risk. Immediate patching and strict access controls are strongly recommended as there is no direct workaround.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox