Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
embedded-device-vulnerabilitywidely-deployed-product-advisoryidentity-authentication-vulnerabilitydetection-content-update

Critical Cisco IMC Flaws Enable Authentication Bypass and Root Compromise

Updated 3mo agoFirst seen Apr 2, 20268 sources

Cisco disclosed multiple vulnerabilities in its Integrated Management Controller (IMC), including the critical CVE-2026-20093, which allows a remote, unauthenticated attacker to send a crafted HTTP request to bypass authentication and change passwords for existing users, including the primary Admin account. Cisco rated the flaw CVSS 9.8 and said no workarounds or mitigations are available, making vendor-issued software updates the only effective fix; the company added that it has no evidence of active exploitation or public malicious use.

Additional advisories cover CVE-2026-20094 through CVE-2026-20097, spanning command injection and arbitrary code execution issues that could let attackers execute commands or code as root and fully compromise affected systems. Impacted products include Cisco UCS C-Series and S-Series servers, UCS E-Series systems, Catalyst 8300 Series Edge uCPE, 5000 Series ENCS, and other Cisco appliances built on vulnerable UCS platforms, with Cisco publishing fixed-version guidance and upgrade paths while runZero released an inventory query to help organizations identify exposed IMC assets.

Share:
Critical Cisco IMC Flaws Enable Authentication Bypass and Root Compromise
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 3, 20263mo ago

Cisco patches critical SSM On-Prem and high-severity EPNM vulnerabilities

Cisco released fixes for additional vulnerabilities beyond IMC, including critical CVE-2026-20160 in Smart Software Manager On-Prem that could allow remote command execution as root, plus high-severity flaws affecting SSM On-Prem and Evolved Programmable Network Manager. Cisco PSIRT said it was not aware of active exploitation or public proof-of-concept code for these issues at disclosure time.

Cisco Patches Two Critical and Six High-Severity Vulnerabilities - TheCyberThrone
Apr 2, 20263mo ago

runZero publishes asset discovery guidance for affected Cisco IMC systems

runZero published analysis of the Cisco IMC advisories along with a software inventory query to help organizations identify potentially vulnerable Cisco IMC assets. The guidance covered affected Cisco UCS servers, NFVIS releases, and appliances built on vulnerable UCS platforms.

Cisco says it has no evidence of active exploitation

In its disclosure, Cisco stated it had no evidence that the IMC vulnerabilities were being actively exploited or used maliciously in public at the time of publication. This applied to the newly disclosed flaws, including the critical password-change bypass issue.

Cisco releases software updates for CVE-2026-20093 and related IMC flaws

Cisco released fixed software and version guidance to address the IMC vulnerabilities, including the critical CVE-2026-20093 authentication bypass rated CVSS 9.8. Cisco said no workarounds or mitigations were available and that vendor-provided updates were the only effective remediation.

Cisco discloses multiple Cisco IMC vulnerabilities

Cisco disclosed two security advisories for five vulnerabilities in its Integrated Management Controller (IMC): CVE-2026-20093, CVE-2026-20094, CVE-2026-20095, CVE-2026-20096, and CVE-2026-20097. The issues included an unauthenticated password-change authentication bypass, command injection flaws, and an arbitrary code execution vulnerability affecting various UCS-based platforms and appliances.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.