Skip to content
Critical Cisco IMC Vulnerability Allows Full Admin Access via Authentication Bypass

Critical Cisco IMC Vulnerability Allows Full Admin Access via Authentication Bypass

First seen 2 Apr 2026, 09:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 3, 2026 at 07:46 UTC
  • •CVE-2026-20093 allows full admin access via authentication bypass on Cisco IMC.
  • •Patches are urgently recommended as there are no temporary mitigations available.
  • •Related vulnerabilities have been actively exploited, raising concerns for unpatched systems.

Cisco Systems has disclosed a critical authentication bypass vulnerability, CVE-2026-20093, affecting its Integrated Management Controller (IMC) with a CVSS score of 9.8. This flaw allows unauthenticated remote attackers to send crafted HTTP requests to vulnerable Cisco UCS C-Series and E-Series servers, enabling them to bypass authentication and gain full administrative access. The vulnerability arises from improper handling of password change requests within the IMC interface. Cisco has not observed any active exploitation but strongly advises all customers to apply the patches immediately, as there are no workarounds available. Additionally, Cisco addressed another critical vulnerability, CVE-2026-20160, which allows remote code execution on its Smart Software Manager On-Prem solution. The urgency of the situation is heightened by the recent exploitation of a related vulnerability, CVE-2026-20131, by the Interlock ransomware group. Security professionals are on alert due to the potential for rapid exploitation of such vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 189d ago How this analysis works

Timeline

2026-03-04
CVE-2026-20131 published
2026-03-06
First public PoC for CVE-2026-20131 released
2026-03-19
CVE-2026-20131 added to CISA KEV for active exploitation
2026-04-01
CVE-2026-20093 published
2026-04-01
Patches released for CVE-2026-20093 and CVE-2026-20160

More articles in this cluster (6)

Following this threat?

Track Interlock, Cisco and CVE-2026-20093 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed