Skip to content

Cisco Identity Services Engine (ISE) β€” Security Intelligence & Vulnerability Profile


ParameterTechnical Specification
Official NameCisco Identity Services Engine (ISE)
Vendor / Projectcisco
Canonical IDcisco:identity_services_engine
Versioning Schemegeneric
CPE Identifierscpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine_software:*:*:*:*:*:*:*:*
Overall PostureCRITICAL
Recommended Safe Release3.4 Patch 2

Documented CVEs

5 vulnerabilities cataloged in the Hermes intelligence repository.

CISA KEV Entries

1 flaws with confirmed active in-the-wild exploitation.

Weaponized Exploits

5 vulnerabilities with publicly available PoCs or weaponized exploit tooling.

Remediation Target

Recommended upgrade to 3.4 Patch 2 to neutralize known flaws.


Progression of Hermes Threat Score (HTS) posture and maximum EPSS probability over the last 30 days:

Current HTS Score

0 / 100

= Stable over 30d

Max EPSS (Exploitation)

97.2 %

= Stable over 30d

CISA KEV Activity

1

Active in-the-wild exploitation

HTS Trend Curve (D-30 β†’ Today)2026-08-12 β†’ 2026-09-10
2026-09-10: CVE: CVE-2026-20180

3. Vulnerability History & Version Applicability Matrix

Section titled β€œ3. Vulnerability History & Version Applicability Matrix”
CVECVSS ScoreEPSS ProbabilityCISA KEVAffected VersionsFixed InHermes Analysis
CVE-2025-2028110 (CRITICAL)97.2%CISA KEV< v3.3.0.430-P7, < v3.4.0.608-P23.3 Patch 7, 3.4 Patch 2Analysis β†’
CVE-2026-2019210 (CRITICAL)0.4%NovAll supported production branches to vISE 3.4 prior to Patch 1-Analysis β†’
CVE-2026-203079.9 (CRITICAL)1.0%NovAll supported production branches to vISE 3.4 prior to Patch 1-Analysis β†’
CVE-2026-201479.8 (CRITICAL)10.4%No< v3.3.13.3.1Analysis β†’
CVE-2026-201808.8 (HIGH)6.0%No< v3.3.13.3.1Analysis β†’

Vulnerabilities impacting Cisco Identity Services Engine (ISE) are actively leveraged in real-world intrusion campaigns:


Are you operating Cisco Identity Services Engine (ISE) in your infrastructure? Inspect your running build to evaluate applicability, confidence score, and security deltas: