logo

Critical Cisco IMC auth bypass gives attackers Admin access

ID: da746573-112c-52f6-bcc2-87a8a0541c06

STIX ID: report--da746573-112c-52f6-bcc2-87a8a0541c06

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-04-02

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cisco released security updates to remediate multiple critical flaws, including an IMC authentication bypass (CVE-2026-20093) that can allow unauthenticated attackers to gain Admin access and an SSM On-Prem RCE (CVE-2026-20160); the advisory also references a previously exploited Secure Firewall RCE (CVE-2026-20131) used by the Interlock ransomware group and urges immediate patching as there are no available workarounds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.