CVE-2026-20093Patch

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 40 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user.

6.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 10 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 91 mentions across 13 observed days

What's happening

  • Active exploitation reported across 10 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 58 signals
  • Technical details provided in 85 signals
  • Disclosure: 39 classified signals
  • General: 7 classified signals
  • Peaked 11d ago at 40 mentions (2026-04-02); latest day: 1
  • 91 total mentions across 13 days

Deep dive

Activity timeline91 mentions / 13d
010203040Mentions · 2026-04-01: 1Mentions · 2026-04-02: 40Mentions · 2026-04-03: 29Mentions · 2026-04-04: 8Mentions · 2026-04-05: 3Mentions · 2026-04-06: 2Mentions · 2026-04-07: 2Mentions · 2026-04-09: 1Mentions · 2026-04-13: 1Mentions · 2026-04-15: 1Mentions · 2026-04-18: 1Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-02: 1Active Exploitation · 2026-04-02: 7Active Exploitation · 2026-04-03: 1Active Exploitation · 2026-04-22: 1Active Exploitation · 2026-04-23: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-02: 31Patch / Workaround · 2026-04-03: 16Patch / Workaround · 2026-04-04: 5Patch / Workaround · 2026-04-05: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-07: 2Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 38Technical Details · 2026-04-03: 29Technical Details · 2026-04-04: 7Technical Details · 2026-04-05: 2Technical Details · 2026-04-06: 2Technical Details · 2026-04-07: 2Technical Details · 2026-04-09: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-0104-0204-0304-0404-0504-0604-0704-0904-1304-1504-1804-2204-23
Signal classification4 categories
Patch
3942.9%
Disclosure
3942.9%
General
77.7%
Active Exploitation
66.6%
Referenced assets50 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-011
Patch1
2026-04-0240
Active Exploitation3Disclosure18General1Patch18
2026-04-0329
Active Exploitation1Disclosure16General1Patch11
2026-04-048
Disclosure1General2Patch5
2026-04-053
Disclosure1General1Patch1
2026-04-062
Disclosure1Patch1
2026-04-072
Patch2
2026-04-091
Disclosure1
2026-04-131
Disclosure1
2026-04-151
General1
2026-04-181
General1
2026-04-221
Active Exploitation1
2026-04-231
Active Exploitation1
Full discourse20 posts
  • CERT Polska@CERT_Polska
    Disclosure

    ❗Uwaga! Krytyczna podatność w Cisco IMC ❗ Podatność CVE-2026-20093 o CVSS 9.8 umożliwia przejęcie konta administratora poprzez przesłanie odpowiednio przygotowanego żądania HTTP. Podatny moduł jest integralną częścią bardzo wielu urządzeń tej firmy - szacujemy, że w Polsce problem może dotknąć od kilkunastu do kilkudziesięciu tysięcy urządzeń. Jeśli jesteś administratorem, apelujemy: zweryfikuj swoją infrastrukturę i zadziałaj jeszcze przed świątecznym weekendem! 🔗 Więcej szczegółów: https://moje.cert.pl/komunikaty/2026/40/krytyczna-podatnosc-w-oprogramowaniu-cisco/

    Post summary

    The post announces the critical Cisco IMC vulnerability CVE‑2026‑20093, providing its CVSS score and admin takeover impact, but does not mention a PoC, exploit tool, patch, or active exploitation.

    2140751812.9K
    35.0K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🚨 تحذير : ثغرة حرجة في Cisco IMC رقم الثغرة: CVE-2026-20093 التقييم: 9.8 من 10 (حرجة جداً) النوع: تجاوز مصادقة كامل (Authentication Bypass) التفاصيل 🧵👇 https://t.co/qs71cphSJ7

    Post summary

    A critical authentication bypass vulnerability (CVE-2026-20093) in Cisco IMC has been disclosed with a 9.8 CVSS score, but the post does not include a PoC, exploit code, active exploitation report, or patch details.

    11020234.0K
    49.2K followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-20093 (CVSS 9.8): Critical Cisco IMC auth bypass gives attackers Admin access 📊 1.1K Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Cisco%20Integrated%20Management%20Controller%22 👇Query HUNTER : http://product.name="Cisco Integrated Management Controller" 📰Refer:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-auth-bypass-AgG2BxTn https://www.bleepingcomputer.com/news/security/critical-cisco-imc-auth-bypass-gives-attackers-admin-access/ https://thehackernews.com/2026/04/cisco-patches-98-cvss-imc-and-ssm-flaws.html #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The statement announces the discovery of a critical authentication bypass in Cisco IMC (CVE‑2026‑20093), providing its CVSS score and linking to vendor and media advisories, but does not disclose PoC code, exploit tools, or active exploitation evidence.

    0402692.2K
    25.9K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Cisco patches a critical 9.8 CVSS flaw (CVE-2026-20093) in IMC. Unauthenticated attackers can change admin passwords and seize full control. Update now! #Cisco #IMC #CVE202620093 #CyberSecurity #InfoSec #Networking #AdminLockout #Vulnerability #PatchNow https://securityonline.info/cisco-imc-critical-authentication-bypass-cve-2026-20093/ https://t.co/sAS2WCAgGR

    Post summary

    The tweet informs that Cisco has released a patch for CVE‑2026‑20093, a critical authentication bypass in IMC that allows password changes and full system control, and urges users to update immediately.

    080101742
    12.3K followersView on X
  • HostingTech@HostingTechNet
    Patch

    Cisco Patches Two Critical Vulnerabilities CVE-2026-20160 and CVE-2026-20093 https://hostingtech.net/cisco-patches-two-critical-vulnerabilities-cve-2026-20160-and-cve-2026-20093/ via @HostingTech https://t.co/WwSxw7H7uh

    Post summary

    The tweet announces that Cisco has released patches for two critical CVEs (CVE‑2026‑20160 and CVE‑2026‑20093).

    000120138
    183 followersView on X
  • EcuCERT@EcuCERT_EC
    Disclosure

    Cisco reporta dos fallas críticas (CVE-2026-20093 y CVE-2026-20160) que permiten a atacantes no autenticados ejecutar comandos, escalar privilegios y obtener acceso administrativo Mas información: https://www.ecucert.gob.ec/wp-content/uploads/2026/04/Al-2026-017-Fallas-criticas-en-Cisco-IMC-y-SSM-On-Prem-CVE-2026-20093-y-CVE-2026-20160.pdf #PorUnEcuadorCiberseguro @Arcotel_ec @CsirtCEDIA @CsirtEPN https://t.co/7fmMdJ6LNK

    Post summary

    Cisco has disclosed two critical vulnerabilities that let unauthenticated attackers execute arbitrary commands and gain admin privileges. No PoC, exploit code, or patch information is provided in the tweet.

    00021326
    2.0K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    General

    Cisco IMC auth bypass vulnerability allows attackers to alter user passwords (CVE-2026-20093) https://www.helpnetsecurity.com/2026/04/03/cisco-imc-vulnerability-cve-2026-20093/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    A tweet cites Cisco’s IMC authentication bypass (CVE‑2026‑20093) that lets attackers change passwords, linked to an external article but offering no further technical detail or patch information.

    01020669
    194.4K followersView on X
  • TechPio@techpio_team
    Patch

    ⚠️ Cisco Patches Critical 9.8 CVSS Vulnerabilities A new IMC & SSM flaw (CVE-2026-20093) could allow remote attackers to gain privileged access. Patches released — update immediately. 🔗 https://thehackernews.com/2026/04/cisco-patches-98-cvss-imc-and-ssm-flaws.html #CyberSecurity #Cisco #CVE2026 #VulnerabilityAlert #InfoSec https://t.co/G6dmpFqXqw

    Post summary

    Cisco has released patches for the critical CVE‑2026‑20093 flaw (CVSS 9.8) that enables remote privileged access; users are urged to update immediately.

    0101180
    395 followersView on X
  • UWillC@uwillc
    Active Exploitation

    5 Cisco critical CVEs in 14 days. No April bundle. All out-of-band. CVE-2026-20131 (FMC, 10.0): Interlock ransomware zero-day since Jan 26. CVE-2026-20093 (IMC, Apr 2): unauthenticated admin password change.

    Post summary

    Several Cisco CVEs have been reported, including a ransomware zero‑day in FMC that has reportedly been actively exploited, though no PoC or patch information is provided.

    10001103
    504 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Cisco ❗ CVE-2026-20160 ❗ CVE-2026-20094 ❗ CVE-2026-20093 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cisco-13/ https://t.co/4iMQautx5v

    Post summary

    Three Cisco CVEs are listed with links to further information, but the post lacks any exploit details or advisory information.

    00020120
    6.7K followersView on X
  • Atarus@Atarussecurity
    Patch

    Cisco's week: source code stolen via Trivy. 3M Salesforce records with government data extorted by ShinyHunters. European Commission breached. April 3 deadline passed. Now a CVSS 9.8 authentication bypass in their server management platform. CVE-2026-20093. One HTTP request resets any password, including Admin. No authentication required. The Cisco IMC runs below the OS on its own firmware. Your EDR cannot see it. Your SIEM does not log it. 50+ appliances affected. Patch today. Full analysis from Atarus Research: https://www.atarussecurity.com/post/cisco-s-week-from-hell-is-not-over-a-cvss-9-8-authentication-bypass-in-their-server-management-plat

    Post summary

    CVE‑2026‑20093 is a CVSS‑9.8 authentication bypass affecting Cisco’s IMC firmware, allowing password reset via a single HTTP request. A patch was released today.

    01010213
    10 followersView on X
  • Atarus@Atarussecurity
    Patch

    Cisco's week: source code stolen via Trivy. 3M Salesforce records with government data extorted by ShinyHunters. European Commission breached. April 3 deadline passed. Now a CVSS 9.8 authentication bypass in their server management platform. CVE-2026-20093. One HTTP request resets any password, including Admin. No authentication required. The Cisco IMC runs below the OS on its own firmware. Your EDR cannot see it. Your SIEM does not log it. 50+ appliances affected. Patch today. Full analysis from Atarus Research: https://www.atarussecurity.com/post/cisco-s-week-from-hell-is-not-over-a-cvss-9-8-authentication-bypass-in-their-server-management-plat

    Post summary

    The post announces CVE-2026-20093, a high-severity authentication bypass, highlights available patches, but does not provide PoC or evidence of active exploitation.

    01010188
    10 followersView on X
  • z3n@zench4n
    General

    3/ For AI systems interfacing with hardware (e.g., CVE-2026-20093 in Cisco IMC), deep dives must include firmware/hardware trust chains. Most AI security tools miss low-level I/O attacks that bypass ML model protections.

    Post summary

    The post highlights the need to review firmware/hardware trust chains for AI systems that interface with hardware, noting that low‑level I/O attacks can bypass ML protections.

    2000038
    1.4K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-20093 (CVSS 9.8) allows unauthenticated attackers to bypass authentication and gain admin access to Cisco IMC via crafted password reset requests. Affects UCS C/E-Series servers and dozens of appliances. #DFIR_Radar https://t.co/eyaACBvSKm

    Post summary

    CVE-2026-20093 is a high‑severity CVSS 9.8 vulnerability that permits unauthenticated attackers to bypass authentication and gain admin access to Cisco IMC via crafted password reset requests, impacting UCS C/E‑Series servers and related appliances.

    10010145
    1.2K followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Cisco Integrated Management Controller (IMC) Authentication Bypass (CVE-2026-20093) 📅 **Timeline:** Disclosure: 2026-04-01, Patch: 2026-04-01 🆔 **CVE-2026-20093** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: 8.76% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** 5000 Series ENCS <4.15.5, Catalyst 8300 Edge uCPE <4.18.3, UCS C‑Series M5/M6 (standalone) <4.3(2.260007)/4.3(6.260017)/6.0(1.250174), UCS E‑Series M3 <3.2.17, UCS E‑Series M6 <4.15.3 🔧 **Fixed Versions:** 5000 Series ENCS: 4.15.5, Catalyst 8300 Edge uCPE: 4.18.3, UCS C‑Series M5/M6 (standalone): 4.3(2.260007)/4.3(6.260017)/6.0(1.250174), UCS E‑Series M3: 3.2.17, UCS E‑Series M6: 4.15.3 🫨 **Attack Vectors:** - Unauthenticated remote HTTP request to IMC password-change endpoint - Remote attacker crafts HTTP request to bypass authentication and change any user password (including Admin) 📝 **Summary:** An authentication-bypass in Cisco IMC’s password-change handling allows an unauthenticated attacker to craft an HTTP request that changes any account password (including Admin). Successful exploitation grants full administrative access to IMC, enabling configuration changes, persistence, and lateral movement to managed systems. 📈 **Impact Scope:** Successful exploitation permits full administrative access to IMC (credential takeover), allowing configuration changes, persistent access, and potential lateral movement to managed infrastructure. 🛡️ **Recommended Actions:** - Apply vendor-provided fixed releases immediately (see advisory links) - Isolate IMC management interfaces from untrusted networks, rotate affected and linked administrative credentials after patching, enable MFA where available, and monitor logs/SIEM for suspicious password-change events 🪢 **Related Resources:** - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-auth-bypass-AgG2BxTn - https://thehackernews.com/2026/04/cisco-patches-98-cvss-imc-and-ssm-flaws.html 🏷 **Tags:** #Cybersecurity #CiscoIMC #CVE2026-20093

    Post summary

    Cisco released a critical authentication‑bypass flaw (CVE-2026-20093) in IMC, with detailed attack vectors and high CVSS, and immediate vendor patches are available.

    0002074
    277 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Cisco patches critical auth bypass (CVE-2026-20093) in IMC allowing attackers Admin access to UCS servers. Fixes also address RCE in Smart Software Manager and FMC, linked to Interlock and Trivy attacks. #CiscoIMC #SupplyChain #USA https://ift.tt/wu3XoEP

    Post summary

    Cisco has released patches for CVE‑2026‑20093 affecting its IMC product, also addressing related RCE flaws in Smart Software Manager and FMC, with documented active exploitation by Interlock and Trivy operators.

    00011175
    3.9K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Cisco IMC の認証バイパス脆弱性 CVE-2026-20093 (CVSS 9.8):管理者権限の奪取の恐れ https://iototsecnews.jp/2026/04/02/cisco-warns-of-critical-imc-vulnerability-enabling-authentication-bypass/ この脆弱性 CVE-2026-20093 は、サーバの管理を担う Integrated Management Controller (IMC) ソフトウェアにおいて、パスワード変更のリクエストを正しく処理できないことに起因します。本来であれば厳重に守られるべき管理者のパスワードが、外部からの不正な HTTP リクエストにより上書きされるため、認証の回避とシステムの完全な制御奪取というリスクが生じます。きわめて重要な管理インターフェイスにおいて、入力された情報の検証や処理が不十分であるため、きわめて大きな問題が引き起こされる可能性があります。ご利用のチームは、ご注意ください。 #Cisco #CVE202620093 #IntegratedManagementController #Vulnerability

    Post summary

    The post announces a critical authentication‑bypass flaw in Cisco IMC software (CVE‑2026‑20093) and outlines its technical details but does not provide PoC code, exploits, active‑usage evidence, or a patch.

    01000156
    483 followersView on X
  • z3n@zench4n
    General

    For AI agents handling sensitive ops (e.g., Cisco IMC's CVE-2026-20093), implement strict auth checks before processing Q&amp;A inputs. Treat user prompts as potential attack vectors.

    Post summary

    The post issues a general recommendation to require strict authentication checks for AI agents handling sensitive operations, referencing CVE‑2026‑20093 but providing no further exploit, patch, or technical details.

    1000044
    1.4K followersView on X
  • Techgines@nxtgen579255
    General

    The pattern is becoming impossible to ignore. Last week: CitrixBleed 3.0 — attackers scanning NetScaler SAML management interfaces (CVE-2026-3055). https://www.techgines.com/post/cisco-imc-authentication-bypass-cve-2026-20093-when-the-hardware-management-layer-becomes-the-attac #ZeroTrust #BMCSecurity #CiscoUCS #Infosec #TechGines https://t.co/TXBKPs4nz4

    Post summary

    The tweet mentions a CVE and a general vulnerability pattern but provides no PoC, exploitation code, patch, or detailed technical information.

    0001050
    3 followersView on X
  • Help Net Security@helpnetsecurity
    Disclosure

    Cisco IMC auth bypass vulnerability allows attackers to alter user passwords (CVE-2026-20093) - https://www.helpnetsecurity.com/2026/04/03/cisco-imc-vulnerability-cve-2026-20093/ - @Cisco @ncsc_nl @socradar - #Cisco #HardwareManagement #vulnerability #SecurityUpdate #CyberSecurity #CyberSecurityNews #SecurityNews

    Post summary

    Cisco IMC authentication bypass (CVE‑2026‑20093) lets attackers change user passwords; the tweet reports the discovery but provides no PoC, exploit, patch, or evidence of live attacks.

    00010386
    59.9K followersView on X

Explore more