Cisco fixes critical IMC auth bypass present in many products
Summary
Cisco released patches for a critical vulnerability (CVE-2026-20093) in its Integrated Management Controller (IMC, a dedicated controller embedded in server motherboards that manages servers remotely even when the main operating system is off). The flaw allows unauthenticated attackers to bypass authentication and gain admin access by sending specially crafted HTTP requests to exposed IMC interfaces. The vulnerability affects many Cisco servers and appliances, particularly those with IMC interfaces exposed to local networks or the internet.
Classification
Original source: https://www.csoonline.com/article/4154052/cisco-fixes-critical-imc-auth-bypass-present-in-many-products.html
First tracked: April 3, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 95%