Critical Cisco IMC Bug Exploited with Public PoC
Cisco has fixed a critical vulnerability in its Integrated Management Controller (IMC) that allowed attackers to run commands as root through the controller's web interface. The flaw, identified as CVE-2026-20200, was discovered by Christoph Peil of German security firm NSIDE ATTACK LOGIC during a commissioned assessment.
The IMC is used by data center technicians and admins to manage Cisco UCS C-Series rack servers and S-Series storage servers, even when their operating system is not responding. An attacker with low privileges could exploit the vulnerability by entering crafted inputs to the web-based management interface of the affected software.
A successful exploit would allow the attacker to execute arbitrary commands on the underlying operating system as the root user, giving them control over the server and all systems running on it.
Cisco has provided a fixed release for the vulnerability, but recommends that customers update their products as soon as possible. In the meantime, users can disable the web interface to block the affected attack path.