CVE-2026-20200PoC(cisco / unified_computing_system)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch cisco unified_computing_system systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. 

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-141

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unified_computing_system

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 6 observed days
  • Momentum state: declining

What's happening

  • Exploit tool or code specified in 9 signals
  • PoC mentioned or linked in 15 signals
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 12 signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 11 mentions (2026-08-06); latest day: 1
  • 17 total mentions across 6 days

Affected systems

Vendors
Products
unified_computing_system

38 versions affected across 1 product

Deep dive

Activity timeline17 mentions / 6d
036811Mentions · 2026-08-05: 1Mentions · 2026-08-06: 11Mentions · 2026-08-07: 2Mentions · 2026-08-10: 1Mentions · 2026-08-11: 1Mentions · 2026-08-14: 1PoC Mentioned / Linked · 2026-08-06: 10PoC Mentioned / Linked · 2026-08-07: 2PoC Mentioned / Linked · 2026-08-10: 1PoC Mentioned / Linked · 2026-08-11: 1PoC Mentioned / Linked · 2026-08-14: 1Exploit Tool / Code · 2026-08-06: 5Exploit Tool / Code · 2026-08-07: 2Exploit Tool / Code · 2026-08-10: 1Exploit Tool / Code · 2026-08-11: 1Patch / Workaround · 2026-08-06: 4Patch / Workaround · 2026-08-07: 1Patch / Workaround · 2026-08-10: 1Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-05: 1Technical Details · 2026-08-06: 7Technical Details · 2026-08-07: 1Technical Details · 2026-08-10: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-14: 108-0508-0608-0708-1008-1108-14
Signal classification4 categories
PoC
1164.7%
Patch
423.5%
Disclosure
15.9%
General
15.9%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-08-051
Disclosure1
2026-08-0611
General1Patch2PoC8
2026-08-072
PoC2
2026-08-101
PoC1
2026-08-111
Patch1
2026-08-141
Patch1
Full discourse17 posts
  • Frank@jedisct1
    PoC

    Oh, another vulnerability in a Cisco product. https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/

    Post summary

    The post references a publicly available proof‑of‑concept exploit for a Cisco vulnerability via a link, with no mention of active exploitation, patches, or detailed technical data.

    01070820
    17.7K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    PoC

    Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200) https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    A critical Cisco IMC vulnerability (CVE-2026-20200) now has a publicly available PoC that allows attackers to gain root privileges.

    021111.6K
    195.1K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    PoC exploit code is public for CVE-2026-20200, a Cisco IMC argument injection flaw enabling root RCE. CVSS 8.8. Patch details inside. #Cisco #RCE #CVE #InfoSec #CyberSecurity http://securityonline.info/cisco-imc-vulnerabilities/

    Post summary

    Public PoC exploit code is released for Cisco IMC CVE-2026-20200, enabling root RCE (CVSS 8.8), with patch information provided.

    01030490
    13.0K followersView on X
  • moton@moton
    PoC

    Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200) - Help Net Security - https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/

    Post summary

    The post announces the release of a public PoC and exploit for CVE-2026-20200, confirming root access is possible but no active exploitation or patch details are reported.

    00010214
    728 followersView on X
  • Help Net Security@helpnetsecurity
    PoC

    Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200) - https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/ - @Cisco @CiscoSecure @nsideattack #Datacenter #Enterprise #Exploit #PoC #Vulnerability #Cybersecurity #CybersecurityNews

    Post summary

    A PoC for CVE-2026-20200, a critical Cisco IMC vulnerability granting root, has been published and linked.

    00010969
    60.1K followersView on X
  • Sequretek@sequretek_sqtk
    Patch

    🚨 New Cisco IMC vulnerabilities (CVE-2026-20200 & CVE-2026-20288) can enable root-level command execution in affected environments. Patch, restrict access and review logs. 👉 Explore here. https://www.sequretek.com/resources/threat-advisories/Cisco%20IMC%20Critical%20Argument%20Injection%20Vulnerabilities #Cisco #CVE #Cybersecurity #Sequretek https://t.co/I21dcJNVUU

    Post summary

    The tweet announces new Cisco IMC vulnerabilities that enable root-level command execution and urges users to apply patches, restrict access, and review logs.

    0000074
    876 followersView on X
  • BT Haberler@BTHaberler
    Patch

    Cisco, SD-WAN ve IOS XE'de Üçü CVSS 9.9 Olan 12 Kritik Açığı Kapattı Cisco, iç güvenlik incelemesi kapsamında Catalyst SD-WAN ve IOS XE yazılımlarını etkileyen 12 açığı kapatan güncellemeler yayınladı; SD-WAN tarafındaki üç açık maksimuma yakın CVSS 9.9 aldı! • CVE-2026-20303, CVE-2026-20304 ve CVE-2026-20310 (üçü de CVSS 9.9), sırasıyla giriş doğrulaması ve yol geçişi eksikliği, yetersiz erişim kontrolü ve bağlantı çözümleme sırası hatasından kaynaklanıyor; ayrıca CVSS 8.8'lik açık metin hassas veri depolama sorunu da bulunuyor. • IOS XE tarafında CVE-2026-20267 ile CVE-2026-20273 arasındaki yedi açık, arabellek taşması, komut enjeksiyonu ve giriş doğrulaması eksikliklerini kapsıyor; en yüksek CVSS puanı 9.8. • Cisco, bu açıkların şu ana kadar aktif olarak istismar edildiğine dair bir bilgi bulunmadığını açıkladı; ancak sistem yönetim arabirimini etkileyen ayrı bir açık olan CIMCown (CVE-2026-20200) için halka açık kanıt kodu zaten mevcut. Kurumsal ağların omurgasını oluşturan SD-WAN ve yönlendirici yazılımlarında aynı anda bu kadar çok maksimum puanlı açığın ortaya çıkması, ağ ekiplerinin güncelleme önceliklerini yeniden gözden geçirmesini gerektiriyor. #SiberGüvenlik #Cisco #SDWAN

    Post summary

    Cisco issued updates fixing 12 critical SD‑WAN and IOS XE vulnerabilities with CVSS scores up to 9.9, confirmed no active exploitation to date, and noted publicly available proof code for a related CVE.

    00000128
    38 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    PoC

    🎯 Cisco IMC critical bug gives root access — public PoC already out (CVE-2026-20200) Cisco's Integrated Management Controller (IMC) has a critical flaw allowing attackers to run commands as root through the web interface. Unlike most of this week's Cisco patches, this one already has a public proof-of-concept exploit available. Patch immediately. 🔗 Source: Help Net Security / Cisco #Cisco #IMC #RootAccess #CVE

    Post summary

    The post announces a critical Cisco IMC flaw that permits root access via the web interface, notes that a public proof‑of‑concept exploit already exists, and urges immediate patching.

    00000101
    36 followersView on X
  • キタきつね@foxbook
    PoC

    Cisco IMCの重大な脆弱性により攻撃者がroot権限を取得可能、概念実証(PoC)が公開されました(CVE-2026-20200) Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200) #HelpNetSecurity (Aug 6) https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/

    Post summary

    A PoC has been published and linked for CVE-2026-20200, a critical Cisco IMC flaw that can give attackers root access, but no evidence of active exploitation or patch availability is given.

    00000324
    4.9K followersView on X
  • Jaden Johnson@JadenJohnsNews
    Patch

    🚨 Cisco has released patches for 5 security vulnerabilities, including 4 critical flaws affecting Catalyst SD-WAN, IOS XE, and IMC. While no active exploitation has been reported, a public PoC is available for CVE-2026-20200. Apply updates as soon as possible. https://t.co/alzK4eaPzy

    Post summary

    Cisco has issued patches for five vulnerabilities, including four critical faults in Catalyst SD-WAN, IOS XE, and IMC. A public PoC for CVE-2026-20200 exists, but no active exploitation has been reported.

    00000169
    229 followersView on X
  • Jaden Johnson@JadenJohnsNews
    Patch

    🚨 Cisco has released patches for 5 security vulnerabilities, including 4 critical flaws affecting Catalyst SD-WAN, IOS XE, and IMC. While no active exploitation has been reported, a public PoC is available for CVE-2026-20200. Apply updates as soon as possible. #Cisco #CVE https://t.co/U8dzMESrHt

    Post summary

    Cisco has released patches for five critical vulnerabilities, including CVE-2026-20200, for which a public PoC exists. No active exploitation has been reported, so administrators should apply the updates promptly.

    0000078
    229 followersView on X
  • デジセキュア@dejital_secure
    PoC

    Cisco Integrated Management Controllerの重大な脆弱性(CVE-2026-20200)が修正、Web経由でroot権限奪取可能、PoCも公開済みとのこと。7/30 Cisco FMCに続く管理基盤系連続、緊急パッチが要所です。 https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/ #Cisco

    Post summary

    Cisco has fixed a critical vulnerability in its Integrated Management Controller (CVE-2026-20200) that allowed root access via web, and a public proof‑of‑concept exploiting the flaw is available.

    0000094
    11 followersView on X
  • TokyoBlackHatNews@TYOBlackHatNews
    PoC

    Cisco IMC の重大な脆弱性、攻撃者にroot権限を許してしまう不具合が発覚、PoCも公開済み(CVE-2026-20200) https://blackhatnews.tokyo/archives/128339

    Post summary

    A critical Cisco IMC vulnerability allowing root elevation was discovered; a PoC has been released online.

    0000097
    31 followersView on X
  • Shah Sheikh@shah_sheikh
    PoC

    Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200): Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s… https://www.helpnetsecurity.com/2026/08/06/cisco-imc-cve-2026-20200-public-poc-exploit/?utm_source=dlvr.it&utm_medium=twitter https://t.co/ZZ4xbaUWtN

    Post summary

    A PoC for CVE-2026-20200 has been released, demonstrating that Cisco IMC can be exploited to gain root access. Cisco has subsequently issued a fix for this critical vulnerability.

    0000082
    2.3K followersView on X
  • Eric Vanderburg@evanderburg
    PoC

    Critical #Cisco IMC bug gives attackers root, #PoC is out (CVE-2026-20200) http://securitytc.com/TTtZHc https://t.co/5tYOQLjKGY

    Post summary

    The tweet announces that a proof‑of‑concept for Cisco IMC CVE‑2026‑20200 is available, demonstrating that the bug can grant attackers root access, but does not provide evidence of active exploitation, patches, or detailed technical data.

    00000198
    43.6K followersView on X
  • SecureShield@SecureShield_
    General

    一次情報(NVD): https://nvd.nist.gov/vuln/detail/CVE-2026-20200 参照元(ベンダー等): https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU

    Post summary

    The brief post links only to the NVD entry and the Cisco advisory for CVE-2026-20200, offering no specific details about the vulnerability, exploitation, or mitigation.

    0000075
    25 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-20200 Cisco Integrated Management Controller Argument Injection Vulnerabilities CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-20200 #Cisco #CyberSecurity #InfoSec

    Post summary

    This tweet announces and links to a detailed analysis of CVE-2026-20200, a high-severity argument injection vulnerability in Cisco Integrated Management Controllers, without providing PoC, exploit, or mitigation details.

    0000052
    88 followersView on X
CPE platform detail38 entries

38 of 38 entries

PartVendorProductVersionTarget SWTarget HW
Appciscounified_computing_system4.3\(1.230097\)--
Appciscounified_computing_system4.3\(1.230124\)--
Appciscounified_computing_system4.3\(1.230138\)--
Appciscounified_computing_system4.3\(2.230207\)--
Appciscounified_computing_system4.3\(2.230270\)--
Appciscounified_computing_system4.3\(2.240002\)--
Appciscounified_computing_system4.3\(3.240022\)--
Appciscounified_computing_system4.3\(3.240043\)--
Appciscounified_computing_system4.3\(4.240142\)--
Appciscounified_computing_system4.3\(4.240152\)--
Appciscounified_computing_system4.3\(4.241014\)--
Appciscounified_computing_system4.3\(4.241063\)--
Appciscounified_computing_system4.3\(4.242028\)--
Appciscounified_computing_system4.3\(4.242038\)--
Appciscounified_computing_system4.3\(4.242066\)--
Appciscounified_computing_system4.3\(4.252001\)--
Appciscounified_computing_system4.3\(4.252002\)--
Appciscounified_computing_system4.3\(5.240021\)--
Appciscounified_computing_system4.3\(5.250001\)--
Appciscounified_computing_system4.3\(5.250030\)--
Appciscounified_computing_system4.3\(5.250033\)--
Appciscounified_computing_system4.3\(5.250043\)--
Appciscounified_computing_system4.3\(5.250045\)--
Appciscounified_computing_system4.3\(6.250039\)--
Appciscounified_computing_system4.3\(6.250040\)--
Appciscounified_computing_system4.3\(6.250044\)--
Appciscounified_computing_system4.3\(6.250053\)--
Appciscounified_computing_system4.3\(6.250060\)--
Appciscounified_computing_system4.3\(6.250101\)--
Appciscounified_computing_system4.3\(6.250117\)--
Appciscounified_computing_system4.3\(6.260003\)--
Appciscounified_computing_system4.3\(6.260017\)--
Appciscounified_computing_system6.0\(1.250127\)--
Appciscounified_computing_system6.0\(1.250130\)--
Appciscounified_computing_system6.0\(1.250131\)--
Appciscounified_computing_system6.0\(1.250174\)--
Appciscounified_computing_system6.0\(1.250192\)--
Appciscounified_computing_system6.0\(1.250194\)--

Explore more