# CVE-2026-20130

## Summary

- **CVE ID:** CVE-2026-20130
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-74
- **Published:** Sep 16, 2026
- **Last Modified:** Sep 16, 2026

## Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20130 are related to improper neutralization of special elements issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.

## Affected Products

- Cisco — Cisco Identity Services Engine Software (3.1.0)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p1)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p3)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p2)
- Cisco — Cisco Identity Services Engine Software (3.2.0)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p4)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p5)
- Cisco — Cisco Identity Services Engine Software (3.2.0 p1)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p6)
- Cisco — Cisco Identity Services Engine Software (3.2.0 p2)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p7)
- Cisco — Cisco Identity Services Engine Software (3.3.0)
- Cisco — Cisco Identity Services Engine Software (3.2.0 p3)
- Cisco — Cisco Identity Services Engine Software (3.2.0 p4)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p8)
- Cisco — Cisco Identity Services Engine Software (3.2.0 p5)
- Cisco — Cisco Identity Services Engine Software (3.2.0 p6)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p9)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 2)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 1)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 3)
- Cisco — Cisco Identity Services Engine Software (3.4.0)
- Cisco — Cisco Identity Services Engine Software (3.2.0 p7)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 4)
- Cisco — Cisco Identity Services Engine Software (3.4 Patch 1)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p10)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 5)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 6)
- Cisco — Cisco Identity Services Engine Software (3.4 Patch 2)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 7)
- Cisco — Cisco Identity Services Engine Software (3.4 Patch 3)
- Cisco — Cisco Identity Services Engine Software (3.5.0)
- Cisco — Cisco Identity Services Engine Software (3.4 Patch 4)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 8)
- Cisco — Cisco Identity Services Engine Software (3.2 Patch 8)
- Cisco — Cisco Identity Services Engine Software (3.5 Patch 1)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 9)
- Cisco — Cisco Identity Services Engine Software (3.2 Patch 9)
- Cisco — Cisco Identity Services Engine Software (3.4 Patch 5)
- Cisco — Cisco Identity Services Engine Software (3.5 Patch 3)
- Cisco — Cisco Identity Services Engine Software (3.5 Patch 2)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 10)
- Cisco — Cisco Identity Services Engine Software (3.3 Patch 11)
- Cisco — Cisco Identity Services Engine Software (3.4 Patch 6)
- Cisco — Cisco Identity Services Engine Software (3.2 Patch 10)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p72)
- Cisco — Cisco Identity Services Engine Software (3.1.0 p11)
- Cisco — Cisco ISE Passive Identity Connector (3.2.0)
- Cisco — Cisco ISE Passive Identity Connector (3.1.0)
- Cisco — Cisco ISE Passive Identity Connector (3.3.0)
- Cisco — Cisco ISE Passive Identity Connector (3.4.0)
- Cisco — Cisco ISE Passive Identity Connector (3.5.0)

## References

- [CNA](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T)

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._