Signal is active with 1 mentions in latest observed window
Immediate actions
Patch cisco unified_computing_system systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system as the root user.
Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.
Warning: Critical flaws in #Cisco products. #CVE-2026-20160 CVSS: 9.8. #CVE-2026-20094 #CVE-2026-20095 #CVE-2026-20096 #CVE-2026-20097 and #CVE-2026-20155. These can lead to #RCE, root compromise, or exposure of sensitive session data! https://ccb.belgium.be/advisories/warning-remote-code-execution-vulnerabilities-multiple-cisco-products-patch-immediately #Patch#Patch#Patch
Post summary
The advisory highlights critical Cisco RCE vulnerabilities, lists multiple CVEs with a high CVSS, and emphasizes the need for immediate patching.
⚠️ **Vulnerability Alert:** Cisco IMC multiple vulnerabilities (incl. CVE-2026-20093 authentication bypass)
📅 **Timeline:** Disclosure: 2026-04-01 • Patch: Not Available
🆔 **CVE-2026-20085** | 📊 CVSS: 6.1 (MEDIUM 🟡) | 📈 EPSS: 5.47%
🆔 **CVE-2026-20087** | 📊 CVSS: 4.8 (MEDIUM 🟡) | 📈 EPSS: 9.70%
🆔 **CVE-2026-20088** | 📊 CVSS: 4.8 (MEDIUM 🟡) | 📈 EPSS: 9.70%
🆔 **CVE-2026-20089** | 📊 CVSS: 4.8 (MEDIUM 🟡) | 📈 EPSS: 9.70%
🆔 **CVE-2026-20090** | 📊 CVSS: 4.8 (MEDIUM 🟡) | 📈 EPSS: 9.70%
🆔 **CVE-2026-20093** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 8.77%
🆔 **CVE-2026-20094** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 57.33%
🆔 **CVE-2026-20095** | 📊 CVSS: 6.5 (MEDIUM 🟡) | 📈 EPSS: 24.33%
🆔 **CVE-2026-20096** | 📊 CVSS: 6.5 (MEDIUM 🟡) | 📈 EPSS: 24.33%
🆔 **CVE-2026-20097** | 📊 CVSS: 6.5 (MEDIUM 🟡) | 📈 EPSS: 19.20%
🛠️ **Exploit Maturity:** Not Available
📂 **Affected Versions:** IMC on Cisco UCS C‑Series and related server series (various firmware), IMC in Cisco appliances exposing web UI (APIC, Secure Firewall MC, Cyber Vision, Malware Analytics)
🫨 **Attack Vectors:**
- Network: crafted HTTP requests (unauthenticated or authenticated depending on CVE)
- Reflected and stored XSS via web-management UI
- Command injection / code execution via web-management interface
- Authentication bypass via malformed password-change request (unauthenticated)
📝 **Summary:** CVE-2026-20093 is an unauthenticated auth-bypass in IMC password-change handling that can grant attacker Admin/root and persistent hardware-level (BMC-like) control. Other flaws include multiple XSS and command-injection issues that, if chained or combined with access, enable credential theft, root execution, lateral movement, and full infrastructure compromise.
📈 **Impact Scope:** Compromise enables persistent out-of-band hardware control, credential theft, privilege escalation to root/Admin, lateral movement, and potential large-scale infrastructure or supply-chain disruption if IMC is reachable or insufficiently segmented.
🛡️ **Recommended Actions:**
- Apply Cisco advisories/patches immediately where available
- Isolate IMC interfaces: block Internet exposure, restrict to management VLANs and trusted admin subnets
- Enforce MFA, rotate credentials, audit account/password changes after remediation
- Monitor logs for unauthorized password changes, unexpected root commands, and other IOCs
🪢 **Related Resources:**
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-auth-bypass-AgG2BxTn
- https://advisories.ncsc.nl/2026/ncsc-2026-0106.html
🏷 **Tags:** #Cybersecurity#CiscoIMC#UCS
Post summary
Cisco has announced multiple CVEs against IMC, including a critical unauthenticated authentication bypass (CVE‑2026‑20093) that could grant admin/root and hardware-level control; no patch is yet available, but advisories and mitigation steps are provided.