Documented CVEs
5 vulnerabilities cataloged in the Hermes intelligence repository.
| Parameter | Technical Specification |
|---|---|
| Official Name | Cisco Identity Services Engine (ISE) |
| Vendor / Project | cisco |
| Canonical ID | cisco:identity_services_engine |
| Versioning Scheme | generic |
| CPE Identifiers | cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*cpe:2.3:a:cisco:identity_services_engine_software:*:*:*:*:*:*:*:* |
| Overall Posture | CRITICAL |
| Recommended Safe Release | 3.4 Patch 2 |
Documented CVEs
5 vulnerabilities cataloged in the Hermes intelligence repository.
CISA KEV Entries
1 flaws with confirmed active in-the-wild exploitation.
Weaponized Exploits
5 vulnerabilities with publicly available PoCs or weaponized exploit tooling.
Remediation Target
Recommended upgrade to 3.4 Patch 2 to neutralize known flaws.
Progression of Hermes Threat Score (HTS) posture and maximum EPSS probability over the last 30 days:
0 / 100
= Stable over 30d
97.2 %
= Stable over 30d
1
Active in-the-wild exploitation
| CVE | CVSS Score | EPSS Probability | CISA KEV | Affected Versions | Fixed In | Hermes Analysis |
|---|---|---|---|---|---|---|
| CVE-2025-20281 | 10 (CRITICAL) | 97.2% | CISA KEV | < v3.3.0.430-P7, < v3.4.0.608-P2 | 3.3 Patch 7, 3.4 Patch 2 | Analysis β |
| CVE-2026-20192 | 10 (CRITICAL) | 0.4% | No | vAll supported production branches to vISE 3.4 prior to Patch 1 | - | Analysis β |
| CVE-2026-20307 | 9.9 (CRITICAL) | 1.0% | No | vAll supported production branches to vISE 3.4 prior to Patch 1 | - | Analysis β |
| CVE-2026-20147 | 9.8 (CRITICAL) | 10.4% | No | < v3.3.1 | 3.3.1 | Analysis β |
| CVE-2026-20180 | 8.8 (HIGH) | 6.0% | No | < v3.3.1 | 3.3.1 | Analysis β |
Vulnerabilities impacting Cisco Identity Services Engine (ISE) are actively leveraged in real-world intrusion campaigns:
Are you operating Cisco Identity Services Engine (ISE) in your infrastructure? Inspect your running build to evaluate applicability, confidence score, and security deltas: