logo

Cisco Issues Urgent Patch for Critical IMC Auth Bypass: A CVSS 9.8 Wake-Up Call

ID: 6141ee58-25d3-5471-b9f6-4653cc98b500

STIX ID: report--6141ee58-25d3-5471-b9f6-4653cc98b500

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-02

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-20093, CVSS 9.8) in Cisco Integrated Management Controller (IMC) allows a remote, unauthenticated attacker to send crafted HTTP requests to bypass authentication, change any user’s password (including Admin), and take control of affected systems; the advisory lists numerous impacted Cisco platforms and fixed releases and urges immediate updates or access restrictions while patches are applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.