Critical Cisco IMC Vulnerability Let Attackers Bypass Authentication
ID: 20ae8fa4-d4c8-55d8-b4f4-87265c66d94f
STIX ID: report--20ae8fa4-d4c8-55d8-b4f4-87265c66d94f
Feed Name: cybersecurityNews.com
### Executive Summary — Cisco IMC Critical Vulnerability: Cisco disclosed CVE-2026-20093, a critical (CVSS 9.8) flaw in the Integrated Management Controller (IMC) password-change functionality that allows a remote unauthenticated attacker to send a crafted HTTP request to bypass authentication and reset any user’s password (including admin). A wide range of Cisco devices and appliances that expose the IMC UI are affected; no mitigations exist other than installing Cisco’s provided software updates, and Cisco reports no current evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
