Threat Advisories:
🎧 Podcast: This Month's Threats in 10 Min! Emerging Threat Intel Audio Briefing - Listen & Defend Now →
👥 Play Count: Loading...

Critical Cisco ISE Flaws Actively Exploited in the Wild

Red | Vulnerability Report
Download PDF

Three recently patched critical vulnerabilities in Cisco Identity Services Engine (ISE), tracked as CVE-2025-20281, CVE-2025-20282, and CVE-2025-20337, affect Cisco ISE and its Passive Identity Connector (ISE-PIC), a platform used by organizations to control network access and enforce security policies. Two of the vulnerabilities allow unauthenticated remote attackers to gain root-level access by sending specially crafted API requests, while the third allows malicious files to be uploaded into sensitive system directories for remote code execution. Some of these flaws are now being actively exploited in the wild, and users are urged to update to the fixed versions immediately, as exploitation attempts have already been observed since July 2025.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox