Cisco Patches Critical Security Problems, So Update Now


  • Cisco releases fix for two defects in Identity Services Engine
  • The deficiencies allowed to perform external code, sensitive data exfiltration and more
  • The first pure version of the Identity Services -Motor is 3.4

Cisco has released patches for two vulnerabilities to critical difficulty that plagues its Identity Services Engine (ISE) solution. As the deficiencies can be abused to run arbitrary commands and steal sensitive information, Cisco called on its users to use the corrections as soon as possible.

In a security advice, the network giant said first that it patched a “Deserialization of user-delivered Java Byte Streams” vulnerability traced as CVE-2025-20124, and got a severity of 9.9/10 (critical). By sending a custom serialized Java object to an affected Cisco ise API, an attacker could perform arbitrary commands and raise privileges.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top