Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-20180

42
FAUCET Score

CVE-2026-20180 is a critical remote code execution vulnerability in Cisco Identity Services Engine (ISE) that allows authenticated attackers with Read Only Admin credentials or higher to execute arbitrary operating system commands through insufficient input validation in HTTP requests. The vulnerability enables attackers to gain user-level access to the underlying OS and escalate privileges to root, with potential impacts including complete system compromise and denial of service in single-node deployments that could disconnect unauthenticated endpoints from the network. The vulnerability carries a CVSS 3.1 score of 9.9 (Critical) with a network-based attack vector, low attack complexity, and low privilege requirements, resulting in high confidentiality, integrity, and availability impacts across system boundaries. Exploitation requires only crafted HTTP requests and an attacker with minimal authentication credentials, making it relatively straightforward to exploit from a technical standpoint. This vulnerability is not currently listed on the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog and shows no indicators of active exploitation in the wild. The EPSS score of 0.0026 indicates this CVE is in the lower percentile for real-world exploitation probability, and the vulnerability remains on inactive status from a community attention standpoint. However, the critical CVSS rating and authentication-only barrier to exploitation warrant prompt patching to mitigate potential future exploitation risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.2.0CPE matchmatch criteria
cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*
3.2.0CPE matchmatch criteria
cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:*
3.2.0CPE matchmatch criteria
cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:*
3.2.0CPE matchmatch criteria
cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:*
3.2.0CPE matchmatch criteria
cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
6.38%
Probability of exploitation in next 30 days
EPSS Percentile
92.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0638 is in the 93rd percentile among its peer group of 1,124 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

ciscovendor investigatingvia nvd_reference
View patch

References

sec.cloudapps.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv
Vendor Advisory