CISCO Security Advisory

Published Date: July 17, 2026

CVE: CVE-2025-20204

Advisory Summary

Cisco has identified multiple stored cross-site scripting (XSS) vulnerabilities in the web-based management interface of its Identity Services Engine (ISE) guest portals. These security gaps result from inadequate validation of user inputs, allowing an authenticated attacker with valid administrative credentials to inject and execute malicious scripts in the context of the management interface. Exploiting these flaws can lead to unauthorized script execution and potential exposure of sensitive browser-based information, posing a medium security risk.

🔧 Action Recommended:
Security teams managing Cisco ISE deployments should prioritize patching affected systems with Cisco’s latest security updates to prevent potential exploitation. Continuous monitoring for unusual administrative interface activities is advised until updates are applied.

Reference: Vendor Advisory