Cisco has released patches for two flaws on the Identity front.

Marked as top-level severity, the vulnerabilities are tagged as CVE-2025-20281 and CVE-2025-20282. Both can be exploited for remote code execution (RCE) on the underlying operating system as the root user.

Both bugs affect Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). CVE-2025-20281 affects the current version of ISE and ISE-PIC (3.4) alongside 3.3. Notably, older versions are not affected, casting doubt on the received wisdom that latest always equal safest.

According to Cisco, the two vulnerabilities are not dependent on one another; exploitation of one is not required to exploit the other. In addition, a software release that is affected by one of the two may not be affected by the other.

The company has released software updates that address this vulnerability, and noted there are no workarounds that address this vulnerability. For CVE-2025-20281, it is recommended to upgrade to version 3.3 patch 6 or 3.4 patch 2.

For CVE-2025-20282, customers are advised to upgrade to version 3.4 patch 2.

The bugs come hot on the heels of ISE flaws, which affected AWS, Azure, and OCI earlier this month.

February also saw critical ISE flaws similar to those from Wednesday, with API being the underlying cause of each issue. Automation may be the way forward - but attackers seem to have once again found an all-too-trusting API on Cisco software.