
- CVE-2025-20337 enables unauthenticated remote code execution in Cisco ISE systems
- Attackers deployed custom in-memory web shells with advanced evasion and encryption techniques
- Exploits were widespread and indiscriminate, with no specific industry or actor attribution
“Sophisticated” threat actors have been using a maximum-severity zero-day vulnerability in Cisco Identity Service Engine (ISE) and Citrix systems to deploy custom backdoor malware, experts have claimed.