Skip to content
COOEY

FAIL › dossier

Identity Services Engine

PRODUCT

· dossier confidence 20%

Cisco ISE is a critical network access control product with a documented history of high-severity RCE vulnerabilities in its API, including two critical flaws in 2025 and a 2021 XSS vulnerability.

PROFILE
CategoryProductWhat they doCisco Identity Services Engine (ISE) is a network access control and identity management solution used to authenticate and authorize users and devices on enterprise networks. Websitehttps://www.cisco.com ↗
SECURITY POSTURE

Product has a history of high-severity Remote Code Execution (RCE) vulnerabilities in its API, including two critical flaws in 2025 and a cross-site scripting vulnerability in 2021.

Notable failures
  • CVE-2025-20337: High-severity RCE in ISE API
  • CVE-2025-20281: High-severity RCE with root privileges in ISE API
  • CVE-2021-40121: Medium-severity XSS in ISE web interface
Patterns: Repeated API-level RCE vulnerabilities; Cross-site scripting (XSS) in web interfaces
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2025-07-28 CVE-2025-20337 high Cisco ISE API RCE
2025-07-28 CVE-2025-20281 high Cisco ISE API flaw allows RCE and root privileges
2021-12-10 CVE-2021-44228 critical CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12
Open questions: Are there additional unpatched CVEs in the ISE product line? · What is the current patch status for the July 2025 vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-01 03:44:11.178134+00:00