---
id: CVE-2026-20211
title: >-
  A vulnerability in Cisco ISE could allow an authenticated, remote attacker to
  execute arbitrary commands on the underlying operating system of an affected
  device
summary: >-
  A vulnerability in Cisco ISE could allow an authenticated, remote attacker to
  execute arbitrary commands on the underlying operating system of an affected
  device. To exploit this vulnerability, the attacker must have valid
  high-privilege…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: Cisco
product: Cisco Identity Services Engine Software
affected:
  - identity_services_engine_software 3.1.0
  - identity_services_engine_software 3.1.0 p1
  - identity_services_engine_software 3.1.0 p3
  - identity_services_engine_software 3.1.0 p2
  - identity_services_engine_software 3.2.0
  - identity_services_engine_software 3.1.0 p4
  - identity_services_engine_software 3.1.0 p5
  - identity_services_engine_software 3.2.0 p1
  - identity_services_engine_software 3.1.0 p6
  - identity_services_engine_software 3.2.0 p2
  - identity_services_engine_software 3.1.0 p7
  - identity_services_engine_software 3.3.0
  - identity_services_engine_software 3.2.0 p3
  - identity_services_engine_software 3.2.0 p4
  - identity_services_engine_software 3.1.0 p8
  - identity_services_engine_software 3.2.0 p5
  - identity_services_engine_software 3.2.0 p6
  - identity_services_engine_software 3.1.0 p9
  - identity_services_engine_software 3.3 Patch 2
  - identity_services_engine_software 3.3 Patch 1
  - identity_services_engine_software 3.3 Patch 3
  - identity_services_engine_software 3.4.0
  - identity_services_engine_software 3.2.0 p7
  - identity_services_engine_software 3.3 Patch 4
  - identity_services_engine_software 3.4 Patch 1
  - identity_services_engine_software 3.1.0 p10
  - identity_services_engine_software 3.3 Patch 5
  - identity_services_engine_software 3.3 Patch 6
  - identity_services_engine_software 3.4 Patch 2
  - identity_services_engine_software 3.3 Patch 7
  - identity_services_engine_software 3.4 Patch 3
  - identity_services_engine_software 3.5.0
  - identity_services_engine_software 3.4 Patch 4
  - identity_services_engine_software 3.3 Patch 8
  - identity_services_engine_software 3.2 Patch 8
  - identity_services_engine_software 3.5 Patch 1
  - identity_services_engine_software 3.3 Patch 9
  - identity_services_engine_software 3.2 Patch 9
  - identity_services_engine_software 3.4 Patch 5
  - identity_services_engine_software 3.5 Patch 3
  - identity_services_engine_software 3.5 Patch 2
  - identity_services_engine_software 3.3 Patch 10
  - identity_services_engine_software 3.3 Patch 11
  - identity_services_engine_software 3.4 Patch 6
  - identity_services_engine_software 3.2 Patch 10
  - identity_services_engine_software 3.1.0 p72
  - identity_services_engine_software 3.1.0 p11
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T12:17:25.350'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20211'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57
    label: psirt@cisco.com
  - url: 'https://software.cisco.com'
tags:
  - nvd
  - cve.org
  - csaf
  - vendor-advisory
  - cisco
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T03:57:12.101305Z'
ingestedAt: '2026-09-16T16:37:52.194Z'
epss: 0.00558
epssPercentile: 0.44096
---

## Overview

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials.

This vulnerability is due to insecure deserialization of Java objects by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to&nbsp;root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **cisco-sa-ise-rce-se7bYU57** · Cisco · affected: Cisco Identity Services Engine Software (46 versions) · updated 2026-09-16 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57)
