CVE-2026-20234

CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have c...

Affects 0 products across 1 vendor.

CVSS 3.19.9
EPSS0.4%
Percentile29th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-522: CWE-522
Related Attack Patterns (CAPEC)
CAPEC-102 Session Sidejacking
via CWE-522
CAPEC-474 Signature Spoofing by Key Theft
via CWE-522
CAPEC-509 Kerberoasting
via CWE-522
CAPEC-551 Modify Existing Service
via CWE-522
CAPEC-561 Windows Admin Shares with Stolen Credentials
via CWE-522
Show all 13

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical severity vulnerability (CVE-2026-20234) affects the target system. As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. Th...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-20234?
A critical severity vulnerability (CVE-2026-20234) affects the target system. As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. Th...
What is the CVSS score for CVE-2026-20234?
CVE-2026-20234 has CVSS 9.9 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. EPSS: 0.4%.
Is CVE-2026-20234 actively exploited?
No confirmed active exploitation of CVE-2026-20234 as of 2026-09-29.
How do I remediate CVE-2026-20234?
Apply vendor patches for CVE-2026-20234. Monitor Cisco advisories.
What systems are affected by CVE-2026-20234?
CVE-2026-20234 affects: Cisco.
Vulnerability Details
CVE IDCVE-2026-20234
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Published2026-09-16
Last Modified2026-09-28
ICS Relevance55%
Weakness (CWE)
SourceNVD
Official Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20234 are related to insufficiently protected credentials issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-522.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductAffected Versions
Cisco — —
Cisco Identity Services Engine 3.3.0 3.4.0 3.5.0 ≥ 3.1.0, < 3.3.0
Cisco Identity Services Engine Passive Identity Connector 3.3.0 3.4.0 ≥ 3.1.0, < 3.3.0
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 19 Days
CISA known-exploitedNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Cisco
CVE-2018-0222 10.0 A vulnerability in Cisco Digital Network Architecture (DNA) Center could allo... CVE-2022-20827 10.0 Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV3... CVE-2024-20419 10.0 A vulnerability in the authentication system of Cisco Smart Software Manager ... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2018-0101 10.0 A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Ci...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.9 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →