This document describes Identity Service Engine (ISE) hot patch/hot fix installation.
You must have the basic knowledge of the Cisco Identity Service Engine (ISE).
When a known defect is hit and the fixed release is not yet available, you can make use of Hot Patch which is available in the Download Portal or you can receive it from Cisco TAC. Hot patches must be a last resort if no other possible workarounds are available.
If a known defect is confirmed and it is impacting your environment, you can use a hot patch when there is no known workaround or fixed release.
Typically, there are three hot patch files:
This file must contain the hot patch installation file.
Format:
Examples:
This file is useful for removing the installed hot patch.
Format:
ise-rollback-<bugid>_<version_applicable>_<customer>_<hotpatchversionnum>-SPA.tar.gz
Examples:
This file contains the details, important notes, installation steps, and rollbacks steps specific to the hot patch defect.
You cannot install hot patches from webGUI. To install hot patches, you must have CLI access.
Example: #application install ise-apply-CSCwk61938_Universal_patchall-SPA.tar.gz local

On the CLI, you can see which bundled hot patches are installed by running the #show logging application hotpatch.log command:

Example: application install ise-rollback-CSCwk61938_Universal_patchall-SPA.tar.gz local


| Revision | Publish Date | Comments |
|---|---|---|
3.0 |
25-Aug-2026
|
Updated spelling, grammar, inserted horizontal lines to separate sections for readability, and updated alt text. |
2.0 |
30-Jul-2025
|
Initial Release, formatting and spelling. |
1.0 |
13-Mar-2025
|
Initial Release |