
Cisco has disclosed a medium-severity path traversal vulnerability in Identity Services Engine and ISE-PIC that could let an authenticated remote attacker read or delete arbitrary files with valid administrative credentials.
Tag archive

Cisco has disclosed a medium-severity path traversal vulnerability in Identity Services Engine and ISE-PIC that could let an authenticated remote attacker read or delete arbitrary files with valid administrative credentials.

Cisco has issued an advance notification that security advisories and fixed software details for Identity Services Engine (ISE) and RoomOS will be published on July 15, 2026. Organizations using these products should prepare to review and apply the upcoming updates promptly.

Cisco's April 2025 ISE bulletin grouped several severe flaws around a high-trust identity platform. This alert explains why exposed policy servers deserve fast patching, evidence preservation, and post-fix validation.