Cisco disclosed multiple vulnerabilities in its Integrated Management Controller (IMC), including the critical CVE-2026-20093, which allows a remote, unauthenticated attacker to send a crafted HTTP request to bypass authentication and change passwords for existing users, including the primary Admin account. Cisco rated the flaw CVSS 9.8 and said no workarounds or mitigations are available, making vendor-issued software updates the only effective fix; the company added that it has no evidence of active exploitation or public malicious use.
Additional advisories cover CVE-2026-20094 through CVE-2026-20097, spanning command injection and arbitrary code execution issues that could let attackers execute commands or code as root and fully compromise affected systems. Impacted products include Cisco UCS C-Series and S-Series servers, UCS E-Series systems, Catalyst 8300 Series Edge uCPE, 5000 Series ENCS, and other Cisco appliances built on vulnerable UCS platforms, with Cisco publishing fixed-version guidance and upgrade paths while runZero released an inventory query to help organizations identify exposed IMC assets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Cisco released fixes for additional vulnerabilities beyond IMC, including critical CVE-2026-20160 in Smart Software Manager On-Prem that could allow remote command execution as root, plus high-severity flaws affecting SSM On-Prem and Evolved Programmable Network Manager. Cisco PSIRT said it was not aware of active exploitation or public proof-of-concept code for these issues at disclosure time.
runZero published analysis of the Cisco IMC advisories along with a software inventory query to help organizations identify potentially vulnerable Cisco IMC assets. The guidance covered affected Cisco UCS servers, NFVIS releases, and appliances built on vulnerable UCS platforms.
In its disclosure, Cisco stated it had no evidence that the IMC vulnerabilities were being actively exploited or used maliciously in public at the time of publication. This applied to the newly disclosed flaws, including the critical password-change bypass issue.
Cisco released fixed software and version guidance to address the IMC vulnerabilities, including the critical CVE-2026-20093 authentication bypass rated CVSS 9.8. Cisco said no workarounds or mitigations were available and that vendor-provided updates were the only effective remediation.
Cisco disclosed two security advisories for five vulnerabilities in its Integrated Management Controller (IMC): CVE-2026-20093, CVE-2026-20094, CVE-2026-20095, CVE-2026-20096, and CVE-2026-20097. The issues included an unauthenticated password-change authentication bypass, command injection flaws, and an arbitrary code execution vulnerability affecting various UCS-based platforms and appliances.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceccb.belgium.be
Open sourcethecyberthrone.in
Open sourcerunzero.com
Open sourcecybersecuritynews.com
Open sourcecvereports.com
Open sourcesec.cloudapps.cisco.com
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.