Skip to content

security_identifier

CVE-2025-20337

Identifier for a maximum-severity Cisco Identity Services Engine flaw exploited in July 2025 for remote code execution, used to deploy a web shell disguised as an ISE component.

Current clusters

security3 publishers

Cisco patches an ISE authentication bypass attackers used before the fix existed

CVE-2026-76460 scores a CVSS 10.0, affects Cisco ISE and ISE-PIC in every configuration, and has no workaround. CISA added it to the KEV catalog the day the patches shipped and gave federal agencies three days.

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 70%
Investor
Investor 8%

Reality

Evidence88
Adoption60
Hype gap0
Incentives45
Confidence82