CVE-2026-20234
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have c...
Affects 0 products across 1 vendor.
Show all 13
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical severity vulnerability (CVE-2026-20234) affects the target system. As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. Th...
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-20234?
What is the CVSS score for CVE-2026-20234?
Is CVE-2026-20234 actively exploited?
How do I remediate CVE-2026-20234?
What systems are affected by CVE-2026-20234?
| CVE ID | CVE-2026-20234 |
|---|---|
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| Published | 2026-09-16 |
| Last Modified | 2026-09-28 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Source | NVD |
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20234 are related to insufficiently protected credentials issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-522.
Source: NIST NVD / MITRE CVE Database
| Vendor | Product | Affected Versions |
|---|---|---|
| Cisco | — | — |
| Cisco | Identity Services Engine | 3.3.0 3.4.0 3.5.0 ≥ 3.1.0, < 3.3.0 |
| Cisco | Identity Services Engine Passive Identity Connector | 3.3.0 3.4.0 ≥ 3.1.0, < 3.3.0 |
No patch URL on record. Monitor vendor security advisories directly.
| CISA known-exploited | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Critical Severity - Know Your Exposure
A CVSS 9.9 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Create a free account →