Cybersecuritynews Critical Cisco IMC Vulnerability Allows Full Admin Access via Authentication Bypass
Article Content
- •CVE-2026-20093 allows full admin access via authentication bypass on Cisco IMC.
- •Patches are urgently recommended as there are no temporary mitigations available.
- •Related vulnerabilities have been actively exploited, raising concerns for unpatched systems.
Cisco Systems has disclosed a critical authentication bypass vulnerability, CVE-2026-20093, affecting its Integrated Management Controller (IMC) with a CVSS score of 9.8. This flaw allows unauthenticated remote attackers to send crafted HTTP requests to vulnerable Cisco UCS C-Series and E-Series servers, enabling them to bypass authentication and gain full administrative access. The vulnerability arises from improper handling of password change requests within the IMC interface. Cisco has not observed any active exploitation but strongly advises all customers to apply the patches immediately, as there are no workarounds available. Additionally, Cisco addressed another critical vulnerability, CVE-2026-20160, which allows remote code execution on its Smart Software Manager On-Prem solution. The urgency of the situation is heightened by the recent exploitation of a related vulnerability, CVE-2026-20131, by the Interlock ransomware group. Security professionals are on alert due to the potential for rapid exploitation of such vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Interlock, Cisco and CVE-2026-20093 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical RCE Vulnerabilities Discovered in DB-GPT AI Agent Platform Two critical remote code execution (RCE) vulnerabilities, CVE-2026-51862 and CVE-2026-51869, were identified in version 0.8.0 of the DB-GPT AI agent platform, which serves as a data access layer for autonomous AI agents. CVE-2026-51862, with a CVSS score of 9.1, allows attackers to exploit a directory traversal flaw…
Ransomware Attacks Target Fort Smith and Cumar Marble & Granite On September 15, 2026, the ransomware group Interlock claimed to have compromised the City of Fort Smith, Arkansas, leaking over 5.6 TB of sensitive municipal data. The exposed information includes personal data, law enforcement records, and critical infrastructure details. Separately, on September 11, 2026, the Dark…