Threat Advisory

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks (CVE-2026-20284)

CRITICAL CVSS 9.1 September 16, 2026

What happened

A vulnerability has been identified in the SXP REST API component of Cisco Identity Services Engine (ISE). The issue stems from insufficient validation of user-supplied input, which enables an authenticated attacker to perform SQL injection attacks. Successful exploits may result in unauthorized viewing or modification of data within the device’s underlying database. Additionally, in single-node deployments, exploitation could lead to a denial of service (DoS) condition, rendering the affected node unavailable and preventing access for endpoints that have not yet authenticated. Exploitation requires the attacker to have valid administrative credentials, the SXP service to be enabled, and at least one SXP connection configured on the affected device. The vulnerability can be exploited remotely through an exposed service without user interaction, making it a critical security concern.

Who is affected

Organizations operating Cisco ISE deployments with enabled SXP services are potentially impacted. Affected environments include those where the SXP REST API is accessible over the network. Since remote attack vectors are possible without requiring user action, any organisation with such configurations should consider their environment vulnerable to this vulnerability, provided the attacker has the necessary authenticated access and the SXP service enabled.

Recommended actions

  1. Implement network segmentation and access controls to restrict external and unauthorised network access to the affected service, reducing the attack surface for exploitation.
  2. Review and enforce strict credential management policies to prevent unauthorised use of administrative accounts with high privileges on Cisco ISE devices.
  3. Monitor network traffic for indications of exploitation attempts targeting the exposed SXP REST API endpoints.
  4. Apply available security updates or patches as soon as they become available, following vendor guidance and security advisories.
  5. Disable or restrict the use of the SXP REST API where possible until a patch or workaround is released.

Indicators of compromise

No specific indicators of compromise are currently available at this time.

Affected

Vendors: Cisco

Products: Cisco ISE

Is your organisation exposed?

Argos matches live threat intelligence to your own asset inventory and tells you what actually affects you.

Discover Argos

At a glance

Severitycritical
CVSS9.1
CVECVE-2026-20284
PublishedSeptember 16, 2026
VendorCisco
ProductsCisco ISE

Get in touch

We respond within 1 hour on weekdays
Exeo Logo White Transparent