Three recently patched critical vulnerabilities in Cisco Identity Services Engine (ISE), tracked as CVE-2025-20281, CVE-2025-20282, and CVE-2025-20337, affect Cisco ISE and its Passive Identity Connector (ISE-PIC), a platform used by organizations to control network access and enforce security policies. Two of the vulnerabilities allow unauthenticated remote attackers to gain root-level access by sending specially crafted API requests, while the third allows malicious files to be uploaded into sensitive system directories for remote code execution. Some of these flaws are now being actively exploited in the wild, and users are urged to update to the fixed versions immediately, as exploitation attempts have already been observed since July 2025.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox