Every CVE whose affected-product data names Cisco Identity Services Engine Passive Identity Connector, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVE-2025-20282 — CVSS 10.0 (critical): A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files…
CVE-2026-20147 — CVSS 9.9 (critical): A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the…
CVE-2026-20181 — CVSS 9.1 (critical): A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…
CVE-2026-20190 — CVSS 7.5 (high): A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected…
CVE-2025-20284 — CVSS 6.5 (medium): A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on…
CVE-2025-20283 — CVSS 6.5 (medium): A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on…
CVE-2026-20136 — CVSS 6.0 (medium): A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an…
CVE-2026-20146 — CVSS 5.5 (medium): A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated…
CVE-2026-20148 — CVSS 4.9 (medium): A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the…
CVE-2025-20130 — CVSS 4.9 (medium): A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an…
CVE-2025-20285 — CVSS 4.1 (medium): A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to bypass…