Multiple Vulnerabilities in Cisco Identity Services Engine, ISE Passive Identity Connector, and RoomOS (GovCERT.HK A26-07-32) — Threadlinqs Intelligence
As of 2026-07-18, Multiple Vulnerabilities in Cisco Identity Services Engine, ISE Passive Identity Connector, and RoomOS (GovCERT.HK A26-07-32) is a medium-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-1500 · Severity: MEDIUM · CVSS: 8.8 · Status: ACTIVE · Category: VULNERABILITY
Cisco disclosed seven vulnerabilities on 15-17 July 2026 spanning Identity Services Engine (ISE)/ISE-PIC (an authenticated path-traversal flaw enabling arbitrary file read/delete) and RoomOS
On 15-17 July 2026, Cisco published two coordinated security advisories covering seven CVEs across three product lines, which Hong Kong's GovCERT.HK bundled into standard-tier alert A26-07-32 on 17 July 2026.
The first advisory, cisco-sa-ise-traversal-xNt7wb2Y, discloses CVE-2026-20146, a path-traversal vulnerability (CWE-22) in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The flaw stems from insufficient validation of user-supplied input in the web-based management interface's file-handling logic, allowing an authenticated attacker holding valid administrative credentials to send crafted HTTP requests that traverse outside the intended directory scope to read or delete arbitrary files on the underlying operating system. Exploitation requires prior authentication (PR:H) but no user interaction, giving a CVSS 3.1 base score of 5.5 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N). Because ISE is frequently deployed as the policy/authentication backbone for 802.1X network access control, an attacker who has already obtained admin-level access could use this flaw to pivot into destructive file deletion or to read sensitive configuration/certificate material stored on the appliance filesystem, compounding an existing credential compromise. No workaround exists; fixed releases are 3.3 Patch 12, 3.4 Patch 7 (or hot patch), and 3.5 Patch 4 (or hot patch), all targeted for September 2026, with versions earlier than 3.3 requiring migration to a supported train.
The second advisory, cisco-sa-hardening-roomos-AqNMbEq, bundles six CVEs (CVE-2026-20150, -20153, -20156, -20157, -20158, -20187) found by Cisco's own RoomOS engineering team during an internal, AI-assisted security review of the RoomOS collaboration endpoint operating system (used on Cisco/Webex Room, Desk, and Board video devices). CVE-2026-20150 (CVSS 8.8, CWE-284 Improper Access Control) allows a low-privileged network attacker to bypass intended access restrictions with full confidentiality/integrity/availability impact. CVE-2026-20153 (CVSS 7.5, CWE-20 Improper Input Validation) is unauthenticated and network-exploitable, causing denial of service. CVE-2026-20156 (CVSS 8.1, CWE-119 memory-buffer bounds violation) requires high attack complexity but yields full CIA impact, consistent with a heap/stack overflow primitive in RoomOS media or signaling parsing code. CVE-2026-20157 (CVSS 7.5, CWE-311 Missing Encryption of Sensitive Data) requires adjacent-network positioning and high attack complexity, implying exposure of sensitive data (credentials, session tokens, or media streams) transmitted in cleartext to an attacker who can observe adjacent-segment traffic, e.g. the same local/room network. CVE-2026-20158 (CVSS 7.5, CWE-664 Improper Control of a Resource Through its Lifetime) and CVE-2026-20187 (CVSS 7.5, CWE-703 Improper Handling of Exceptional Conditions) are both unauthenticated, network-reachable denial-of-service vectors, likely triggerable via malformed call-signaling or media packets that RoomOS fails to release/handle cleanly, crashing or hanging the device. All six affect a broad matrix of RoomOS 10.3.2.0 through 11.38.1.1 (RoomOS 11 and earlier, on-prem and cloud-registered) and the RoomOS 26 branch through 26.5.2.0/26.7.1.7. No workarounds are available for any of the six; fixed releases are RoomOS 11.32.6.0 (on-prem) / 11.39.1.1 (cloud-aware), and RoomOS 26.5.2.2 (on-prem) / 26.7.1.7 (June 2026 cloud release).
GovCERT.HK's own publication conventions place this at the lower 'Security Alert' tier rather than 'High Threat Security Alert,' reflecting that none of the seven CVEs carry confirmed active exploitation, and CISA's Known Exploited Vulnerabilities catalog (checked 18 July 2026) contains no entries for any of the seven CVE IDs. The combined risk profile is nonetheless significant for defenders: ISE is core network-access-control infrastructure, and RoomOS devices are frequently deployed in boardrooms/executive spaces with mic
Weaknesses (CWE)
CWE-22, CWE-284, CWE-20, CWE-119, CWE-311, CWE-664, CWE-703
Target sectors: government administration, finance, health, education, technology, telecoms, enterprise-networking, corporate-collaboration
Target regions: Global, Asia Pacific, North America, Europe
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, MEDIUM, threat intelligence, cybersecurity, CVE-2026-20146, CVE-2026-20150, CVE-2026-20153, CVE-2026-20156, CVE-2026-20157, CVE-2026-20158, CVE-2026-20187, T1190, T1203, T1505, T1068, T1211, T1070, T1552, T1557, T1083, T1046