Cisco IMC auth bypass vulnerability allows attackers to alter user passwords (CVE-2026-20093)
ID: 16adedf9-1665-59b7-82ab-1ddae4be258b
STIX ID: report--16adedf9-1665-59b7-82ab-1ddae4be258b
Feed Name: Help Net Security
Threat Score
Cisco released fixes for ten vulnerabilities in its Integrated Management Controller (IMC), notably CVE-2026-20093 — an authentication bypass that can grant unauthenticated remote administrative access — alongside multiple XSS, remote code execution, and privilege escalation flaws affecting many Cisco UCS-based servers and appliances; patches are available and immediate patching plus network segmentation and access controls are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
