logo

Critical Cisco IMC Vulnerability Let Attackers Bypass Authentication

ID: 20ae8fa4-d4c8-55d8-b4f4-87265c66d94f

STIX ID: report--20ae8fa4-d4c8-55d8-b4f4-87265c66d94f

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-02

Date Updated: 2026-04-21

Author: Abinaya

...
...

### Executive Summary — Cisco IMC Critical Vulnerability: Cisco disclosed CVE-2026-20093, a critical (CVSS 9.8) flaw in the Integrated Management Controller (IMC) password-change functionality that allows a remote unauthenticated attacker to send a crafted HTTP request to bypass authentication and reset any user’s password (including admin). A wide range of Cisco devices and appliances that expose the IMC UI are affected; no mitigations exist other than installing Cisco’s provided software updates, and Cisco reports no current evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.