According to the advisory, an API of Cisco ISE is prone to insecure deserialization of user-supplied Java byte streams. A threat actor could exploit this by sending crafted serialized Java object ...
Here are the details on both. The first flaw, CVE-2025-20124, stems from the insecure deserialization of user-supplied Java byte streams in Cisco ISE, which is network access control software that ...