Cisco has released updates that address two critical security vulnerabilities in Identity Services Engine (ISE). These flaws could allow remote attackers execute arbitrary commands on vulnerable devices and elevate privileges.
Below is a list of vulnerabilities.
CVE-2025-20124 – An insecure Java serialization vulnerability in an API for Cisco ISE, which could allow an authenticated remote attacker to gain access.