Cisco patched an ISE/ISE-PIC XML parsing vulnerability (CVE-2026-20029) that allows authenticated admin-level attackers to read arbitrary sensitive files; a public POC exists.
An advanced attacker used CitrixBleed 2 and an undocumented, max-severity Cisco ISE vulnerability as zero-days to deploy custom malware and achieve remote root code execution.
Amazon Uncovers Attacks Exploited Cisco ISE and Citrix NetScaler as Zero-Day Flaws
Advanced threat actor exploited zero-day vulnerabilities in Citrix NetScaler ADC and Cisco ISE to deploy a custom web shell backdoor disguised as IdentityAuditAction.