VDB

GCVE-110-NCSC-2026-382

GCVE-110-NCSC-2026-382
Advisory PublishedCVSS 10.0/10
Vulnetix · Advisory published September 17, 2026
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) allow authenticated attackers with low-privileged admin credentials to execute arbitrary code and commands via insecure deserialization, potentially causing denial of service in single-node deployments.

Weaknesses (CWE)

CWE-502Deserialization of Untrusted DataCWE-23Relative Path TraversalCWE-641Improper Restriction of Names for Files and Other ResourcesCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-669Incorrect Resource Transfer Between SpheresCWE-522Insufficiently Protected CredentialsCWE-648Incorrect Use of Privileged APIs

Risk Scores

CVSS 3.1
10.0/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Ciscovers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

406 records in the GCVE database · Updated September 17, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›