EN

critical CVE-2026-20284

SXP REST API of Cisco ISE: SQL injection and denial of service possible

NVD (NIST) reports one vulnerability in SXP REST API of Cisco ISE with severity critical. The stated impact is SQL injection and denial of service. Affected: CVE-2026-20284. The full description, affected versions and recommended action are available from NVD (NIST).

Attack vector
over the network
Access needed
yes, an account is needed
CVSS
9.1

What this means for you

The application can be used to reach the database behind it. Check the logs before you patch: unusual queries suggest the flaw has already been used.

Original source

NVD (NIST)

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.