CVE-2026-20190: fallo de gravedad alta en Cisco Identity Services Engine Software
Cisco Identity Services Engine Information Disclosure Vulnerability
Publicada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5epss 0.5%
probabilidad de explotación
0.5%top 59% de las CVE
explotación observada
noninguna fuente lo reporta
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.
This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Productos afectados
Cisco · Cisco Identity Services Engine SoftwareCisco · Cisco ISE Passive Identity ConnectorCVEs relacionadas — Cisco Identity Services Engine Software
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-20281CRITICALCisco ISE API Unauthenticated Remote Code Execution VulnerabilityEPSS 97.6%KEVCVE-2025-20337CRITICALCisco ISE API Unauthenticated Remote Code Execution VulnerabilityEPSS 68.0%KEVCVE-2026-76460CRITICALCisco Identity Services Engine Authentication Bypass VulnerabilityEPSS 14.0%KEVCVE-2025-20282CRITICALCisco ISE API Unauthenticated Remote Code Execution VulnerabilityEPSS 38.7%CVE-2022-20964MEDIUMCVE-2022-20964EPSS 30.6%CVE-2022-20966MEDIUMCVE-2022-20966EPSS 27.6%