Cisco disclosed CVE-2026-20200, a high-severity argument injection flaw in the web-based management interface of Cisco Integrated Management Controller (IMC) that allows an authenticated low-privilege attacker to execute arbitrary commands as root. The vulnerability, scored CVSS 8.8, affects multiple Cisco Unified Computing System standalone releases in the 4.3 and 6.0 branches, and Cisco urged customers to apply updates, validate management-interface inputs, and limit privileges for authenticated users.
At the same time, research presented by runZero and reported from Black Hat 2026 warned that baseboard management controllers (BMCs) across major vendors remain broadly exposed and vulnerable to takeover. runZero said it found multiple flaws affecting platforms including OpenBMC, Supermicro IPMI, HPE iLO, Dell iDRAC, AMI MegaRAC, Raritan, H3C HDM, and Fujitsu BMC, while scans cited by Ars Technica identified more than 86,000 Internet-exposed BMCs and found over 54% with at least one critical weakness. Researchers said exploitation can enable persistent server backdoors, lateral movement, and segmentation bypass, and recommended isolating BMC interfaces from the public Internet, monitoring vendor advisories, patching promptly, and disabling legacy management features such as IPMI and KCS where possible.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
After Cisco published its advisory for CVE-2026-20200, researcher Christoph Peil released a public proof-of-concept exploit named CIMCown on GitHub. The PoC demonstrated exploitation of the Cisco IMC flaw that allows a low-privilege authenticated attacker to execute commands as root.
Cisco published a security advisory for CVE-2026-20200, a high-severity argument injection flaw in the web-based Cisco IMC interface. Cisco said the bug can lead to remote code execution and privilege escalation to root, and recommended applying vendor updates.
The vulnerability history states that the CVE-2026-20200 record was newly received by Cisco PSIRT. The flaw affects Cisco Integrated Management Controller and can allow authenticated low-privilege remote attackers to execute commands as root.
At Black Hat 2026, HD Moore presented runZero research describing more than a dozen new BMC vulnerabilities affecting major server vendors. He reported scans showing over 86,000 Internet-exposed BMCs, with more than 54 percent of externally scanned systems and nearly 29 percent of 126,761 internally surveyed BMCs having at least one critical vulnerability.
Researchers discovered the ILObleed implant in HPE server BMC firmware in 2021. The malware used wiper firmware that destroyed hard-drive data and persisted even after OS reinstalls or drive replacement because it lived in the BMC.
A vulnerability later used in the ILObleed compromises had been patched by HPE four years before the 2021 infections. The patch was not installed on the affected devices.
runZero research found that older BMC weaknesses, including CVE-2013-4786, were still broadly exploitable more than a decade later. Ars Technica reported that up to 75,000 publicly exposed BMCs remained vulnerable to the flaw.
Dan Farmer's 2013 research identified architectural weaknesses in IPMI, including Cipher Zero authentication bypasses and RAKP password hash disclosure. Later reporting cited these flaws as still relevant to modern BMC exposure.
runZero announced it had identified multiple vulnerabilities across major BMC implementations including OpenBMC, Supermicro IPMI, HPE iLO, Dell iDRAC, AMI MegaRAC, Raritan, H3C HDM, and Fujitsu platforms. The company said exploitation could enable unauthorized control or disruption, segmentation bypass, lateral movement, and persistence.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcegithub.com
Open sourcearstechnica.com
Open sourcerunzero.com
Open sourcecvefeed.io
Open sourcensideattacklogic.de
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.