Cisco disclosed multiple vulnerabilities in Identity Services Engine (ISE) and ISE-PIC that could let attackers compromise deployments through authentication bypass, unauthenticated remote code execution, and path traversal. One of the issues, tracked as CVE-2025-20281, was described in public research as allowing unauthenticated attackers to achieve remote code execution as root because of insufficient input validation in a specific API, significantly raising the risk to exposed management infrastructure.
Separate Cisco advisories also detailed additional authentication bypass weaknesses and a combination of remote code execution and path traversal flaws affecting the same product line, indicating broad attack surface concerns in enterprise identity and access control environments. The publication of a public GitHub checker for CVE-2025-20281 increases the likelihood of rapid defender validation and potential attacker reconnaissance, making prompt patching, exposure review, and monitoring of Cisco ISE systems a priority for security teams.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Cisco issued a security advisory covering authentication bypass vulnerabilities affecting Cisco Identity Services Engine. The advisory publicly documented the issue and associated remediation guidance.
Cisco released a security advisory for Cisco Identity Services Engine covering remote code execution and path traversal vulnerabilities. The advisory formally disclosed the flaws and provided vendor guidance for affected deployments.
A GitHub repository by grupooruss published a script to check Cisco Identity Services Engine (ISE) and ISE-PIC instances for CVE-2025-20281, described as an unauthenticated remote code execution vulnerability allowing root-level compromise due to insufficient input validation in an API.
Cisco issued a security advisory for Cisco Identity Services Engine covering unauthenticated remote code execution vulnerabilities. The advisory publicly disclosed the flaws and provided vendor guidance for affected deployments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
sec.cloudapps.cisco.com
Open sourcesec.cloudapps.cisco.com
Open sourcegithub.com
Open sourcesec.cloudapps.cisco.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.