← Vulnerability feed

Vulnerability record · CVE-2025-20281 · published 25 June 2025

CVE-2025-20281: Cisco ISE API unauthenticated remote code execution

Cisco · Identity Services Engine

Cisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, allowing a crafted request to reach the underlying operating system. Because the flaw is reachable without credentials and yields root, it is a full compromise of the appliance.

10.0 CVSS 3.1 Critical CISA KEV since 28 Jul 2025 EPSS 98% · top 0.1% CWE-74 · Injection
10.0CVSS 3.1 base score
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable root code execution with CVSS 10, KEV listing and near-certain EPSS probability makes this an urgent patch.

What it is

Cisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, allowing a crafted request to reach the underlying operating system. Because the flaw is reachable without credentials and yields root, it is a full compromise of the appliance.

Impact

An unauthenticated remote attacker gains root-level code execution on the ISE or ISE-PIC host, giving control of the appliance and any identity data or trust relationships it holds.

Attack surface

Reached over the network via a crafted API request; the CVSS vector shows PR:N and UI:N, so no authentication or user interaction is required.

Exploitation

CVE-2025-20281 is listed in CISA KEV with a 2025-08-18 remediation due date, and a third-party advisory carries an Exploit tag; EPSS 30-day probability is 0.9723. No ransomware campaign use is documented.

What to do

  • Apply the Cisco security advisory fix for ISE and ISE-PIC immediately; this is a KEV-listed flaw with a federal due date.
  • If patching cannot be completed at once, restrict network access to the affected API to trusted management networks only.
  • Audit and disable any unnecessary external exposure of ISE management and API interfaces.
  • After patching, rotate credentials and review the appliance for signs of tampering, since root access may have been obtained.
  • Track BOD 22-01 guidance and confirm remediation status against the KEV due date.

Detection

  • Review ISE API and web access logs for crafted or anomalous requests to the affected API endpoint, especially from unexpected source addresses.
  • Monitor for unexpected processes, child processes of web/API services, or new files on the ISE host that indicate command execution.
  • Alert on outbound connections from ISE appliances to unfamiliar hosts, which may indicate post-exploitation activity.
  • Correlate authentication and configuration changes on ISE with API request logs to spot unauthorized administrative activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-20281 to the Known Exploited Vulnerabilities catalog on 28 July 2025 as "Cisco Identity Services Engine Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 18 August 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-20281 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-76460Cisco ISE API authentication bypass via insufficient access controlCisco Identity Services Engine contains an authentication bypass in an API endpoint caused by insufficient authentication control. An unauthenticated…KEVEPSS 14%analysed10.0CVE-2025-20337Cisco ISE API input validation flaw allows unauthenticated root RCECisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, letting an unauthenticated remote attacker execute arbitrary c…KEVEPSS 68%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed10.0CVE-2025-20282Cisco identity services engine improper privilege management vulnerabilityA vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an aff…EPSS 39%10.0CVE-2011-3290Cisco identity services engine vulnerabilityCisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or pe…EPSS 2.3%9.9CVE-2026-20180Cisco identity services engine path traversal vulnerabilityA vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…EPSS 6.0%9.9CVE-2026-20186Cisco identity services engine command injection vulnerabilityA vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…EPSS 5.6%9.9CVE-2026-20147Cisco identity services engine passive identity connector command injection vulnerabilityA vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operatin…EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2025-20281), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.