Vulnerability Details CVE-2026-20130
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20130 are related to improper neutralization of special elements issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 31.1%
CVSS Severity
CVSS v3 Score 10.0
Products affected by CVE-2026-20130
-
cpe:2.3:a:cisco:identity_services_engine:3.3.0
-
cpe:2.3:a:cisco:identity_services_engine:3.4.0
-
cpe:2.3:a:cisco:identity_services_engine:3.5.0
-
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0
-
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0