
- CVE-2026-20029 in Cisco ISE/ISE-PIC allows arbitrary file reads via malicious XML uploads
- Exploitation requires valid admin credentials; no workarounds exist—patching is the only fix
- PoC exploit available; past ISE flaws show attackers actively target enterprise network access controls
Cisco has patched a medium-severity vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), for which there is a proof-of-concept (PoC) exploit.