critical CVE-2026-20284
SXP REST API of Cisco ISE: SQL injection and denial of service possible
NVD (NIST) reports one vulnerability in SXP REST API of Cisco ISE with severity critical. The stated impact is SQL injection and denial of service. Affected: CVE-2026-20284. The full description, affected versions and recommended action are available from NVD (NIST).
- Attack vector
- over the network
- Access needed
- yes, an account is needed
- CVSS
- 9.1
What this means for you
The application can be used to reach the database behind it. Check the logs before you patch: unusual queries suggest the flaw has already been used.
Original source
Insights
More articles
Weekly situation, week 37: 117 advisories, 24 critical
Between 6 Sep and 13 Sep 2026 our sources recorded 117 advisories: 24 critical, 93 high.
Weekly situation, week 36: 55 advisories, 12 critical
Between 30 Aug and 6 Sep 2026 our sources recorded 55 advisories: 12 critical, 43 high.
Weekly situation, week 35: 75 advisories, 21 critical
Between 23 Aug and 30 Aug 2026 our sources recorded 75 advisories: 21 critical, 54 high.
Contact
Reputation takes years. Destruction takes seconds.
Talk to us before somebody else does. The first conversation is free and we reply the same business day.