OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-20284

CRITICAL · CVSS 9.1 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A vulnerability in the SXP REST API of Cisco ISE allows authenticated remote attackers to perform SQL injection attacks due to inadequate input validation. Successful exploitation can lead to unauthorized data access or modification, and in single-node setups, it may trigger a denial-of-service condition, preventing unauthenticated endpoints from accessing the network. Organizations using Cisco ISE with enabled SXP services should prioritize patching this critical vulnerability to safeguard their network integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-20284
Severity
CRITICAL
CVSS
9.1
EPSS
0.39%
Cisco

Original NVD Description

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the underlying database for the affected device. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored. To exploit this vulnerability, the attacker must have valid administrative credentials, have the SXP service enabled, and have at least one SXP connection configured.