CVE-2026-20180

CVSS 9.9 · CRITICAL
EPSS p92
Higher than 92% of all CVEs — elevated exploitation risk.
No patch reference
No patch/mitigation in references

Published 4/15/2026 · updated 4/17/2026 · CWE-22

Share
Get asset-aware triage

Summary

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node ISE deployments, successful exploitation of these vulnerabilities could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.

CVSS 9.9CRITICAL

9.9 / 10
  • AV: Network
  • AC: Low complexity
  • PR: Low privileges
  • UI: No user interaction
  • S: Scope changed
  • C: Confidentiality: High
  • I: Integrity: High
  • A: Availability: High

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS exploitation probability

6.0%

Percentile p92 Higher than 92% of all CVEs — elevated exploitation risk.

Timeline

  1. Apr 15, 2026 · Disclosed / published in NVD
  2. Apr 17, 2026 · Intel last updated

Intel sources

Which upstream feeds returned data for this CVE, and when they were last fetched.

  • NVD· 47 days ago
  • CVE.org· no data
  • FIRST EPSS· 47 days ago
  • CISA KEV· no data
  • OSV· 47 days ago

References

Unlock the full report

See how CVE-2026-20180 hits your stack.

Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.

  • · Asset-aware CVSS & priority
  • · Grounded AI analysis (A–D graded)
  • · Auto-generated WAF / IPS rules
  • · Jira, SIEM, Slack, Teams delivery

No credit card · 100 free enrichments · analyst-grade citations.