CVE-2026-20190: high-severity vulnerability in Cisco Identity Services Engine Software
Cisco Identity Services Engine Information Disclosure Vulnerability
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.
This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Cisco · Cisco Identity Services Engine SoftwareCisco · Cisco ISE Passive Identity ConnectorRelated CVEs — Cisco Identity Services Engine Software
In the same product, most dangerous first.
CVE-2025-20281CRITICALCisco ISE API Unauthenticated Remote Code Execution VulnerabilityEPSS 97.6%KEVCVE-2025-20337CRITICALCisco ISE API Unauthenticated Remote Code Execution VulnerabilityEPSS 68.0%KEVCVE-2026-76460CRITICALCisco Identity Services Engine Authentication Bypass VulnerabilityEPSS 14.0%KEVCVE-2025-20282CRITICALCisco ISE API Unauthenticated Remote Code Execution VulnerabilityEPSS 38.7%CVE-2022-20964MEDIUMCVE-2022-20964EPSS 30.6%CVE-2022-20966MEDIUMCVE-2022-20966EPSS 27.6%