logo

Cisco IMC auth bypass vulnerability allows attackers to alter user passwords (CVE-2026-20093)

ID: 16adedf9-1665-59b7-82ab-1ddae4be258b

STIX ID: report--16adedf9-1665-59b7-82ab-1ddae4be258b

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-04-03

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

Cisco released fixes for ten vulnerabilities in its Integrated Management Controller (IMC), notably CVE-2026-20093 — an authentication bypass that can grant unauthenticated remote administrative access — alongside multiple XSS, remote code execution, and privilege escalation flaws affecting many Cisco UCS-based servers and appliances; patches are available and immediate patching plus network segmentation and access controls are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.