logo

Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)

ID: 495b93e1-2344-5ba8-9b1d-e90e1faf448b

STIX ID: report--495b93e1-2344-5ba8-9b1d-e90e1faf448b

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: Zeljka Zorz

...
...

Cisco released fixes addressing several critical vulnerabilities: the highest-risk item is CVE-2026-20200 in Cisco Integrated Management Controller (IMC), which allows authenticated remote command execution as root and has a public proof-of-concept, while separately Cisco published hardening releases for AI-discovered critical flaws in IOS XE and Catalyst SD-WAN (multiple CVE groupings rated 9.8–9.9); customers are urged to update affected systems and avoid exposing management interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.