CVE-2025-20281 : Critical RCE in Cisco ISE Sees a Second Life
3 Articles
3 Articles
CrowdSec Threat Intelligence reports a new wave of active exploitation of CVE-2025-20281, an NCE-type critical vulnerability affecting Cisco Identity Services Engine (ISE), noted CVSS 10.0. After a first phase of targeted exploitation during its disclosure in June 2025, an opportunistic increase was observed from 23 February 2026, the attackers now integrating [...] The post CVE-2025-20281, a new wave of active exploitation of Cisco Identity Ser…
CVE-2025-20281 : Critical RCE in Cisco ISE Sees a Second Life
Here's a snippet of your Monday report on immediate and emerging threats. Powered by the CrowdSec Network. CrowdSec Threat Intelligence has observed a new wave of targeted exploitation attempts centered around CVE-2025-20281. CVE-2025-20281 is a critical Remote Code Execution (RCE) vulnerability in Cisco Identity Services Engine (ISE). In this week's threat alert, we dive into how this vulnerability works, how attackers exploit it, and why it mi…
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium