Critical Cisco IMC auth bypass gives attackers Admin access
ID: da746573-112c-52f6-bcc2-87a8a0541c06
STIX ID: report--da746573-112c-52f6-bcc2-87a8a0541c06
Feed Name: Bleeping Computer
Threat Score
Cisco released security updates to remediate multiple critical flaws, including an IMC authentication bypass (CVE-2026-20093) that can allow unauthenticated attackers to gain Admin access and an SSM On-Prem RCE (CVE-2026-20160); the advisory also references a previously exploited Secure Firewall RCE (CVE-2026-20131) used by the Interlock ransomware group and urges immediate patching as there are no available workarounds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
