{"id":11799,"date":"2026-04-02T10:04:20","date_gmt":"2026-04-02T10:04:20","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/02\/critical-cisco-imc-vulnerability-let-attackers-bypass-authentication\/"},"modified":"2026-04-02T10:04:20","modified_gmt":"2026-04-02T10:04:20","slug":"critical-cisco-imc-vulnerability-let-attackers-bypass-authentication","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/02\/critical-cisco-imc-vulnerability-let-attackers-bypass-authentication\/","title":{"rendered":"Critical Cisco IMC Vulnerability Let Attackers Bypass Authentication"},"content":{"rendered":"<p>    Critical Cisco IMC Vulnerability Let Attackers Bypass Authentication<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cisco has recently disclosed a critical security flaw affecting its <a href=\"https:\/\/cybersecuritynews.com\/cisco-imc-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Integrated Management Controller (IMC)<\/a>, prompting the release of urgent software updates.<\/p>\n<p>The vulnerability, officially tracked as CVE-2026-20093, has been assigned a critical Base CVSS score of 9.8, indicating the highest level of severity.<\/p>\n<p>This security weakness is located in the password change functionality of the Cisco IMC software. The core issue stems from the system\u2019s incorrect processing of incoming password change requests.<\/p>\n<p>By exploiting this flaw, a remote, unauthenticated attacker can send <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">a<a href=\"https:\/\/cybersecuritynews.com\/kea-dhcp-server-vulnerability\/\" target=\"_blank\" rel=\"noopener\">\u00a0maliciously<\/a><\/span> crafted HTTP request directly to an affected device.<\/p>\n<p>If the exploit is successful, the attacker can completely <a href=\"https:\/\/cybersecuritynews.com\/new-telegram-phishing-attack-abuses-authentication-workflows\/\" target=\"_blank\" rel=\"noreferrer noopener\">bypass standard authentication checks<\/a>. Once authentication is bypassed, the attacker can modify the passwords of any existing user on the system.<\/p>\n<p>This includes the primary Admin account, which essentially allows the attacker to <a href=\"https:\/\/cybersecuritynews.com\/attackers-hijacked-200-websites-exploiting-magento-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">hijack the system and gain full administrative access<\/a> as that user.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-affected-systems-and-hardware\"><strong>Affected Systems and Hardware<\/strong><\/h2>\n<p>The vulnerability impacts several Cisco hardware products if they are running a vulnerable release of the Cisco IMC software.<\/p>\n<p>The affected standalone products include:<\/p>\n<ul class=\"wp-block-list\">\n<li>5000 Series Enterprise Network Compute Systems (ENCS)<\/li>\n<li>Catalyst 8300 Series Edge uCPE<\/li>\n<li>UCS C-Series M5 and M6 Rack Servers (in standalone mode)<\/li>\n<li>UCS E-Series Servers M3 and M6<\/li>\n<\/ul>\n<p>Furthermore, numerous Cisco appliances that rely on preconfigured versions of the affected UCS C-Series Servers are also at risk. If these appliances expose the Cisco IMC user interface, they are vulnerable.<\/p>\n<p>This extensive list includes Application Policy Infrastructure Controller (APIC) Servers, Catalyst Center Appliances, <a href=\"https:\/\/cybersecuritynews.com\/cisco-0-day-rce-secure-email-gateway-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Secure Firewall Management Center Appliances<\/a>, and Secure Network Analytics Appliances.<\/p>\n<p>Cisco has confirmed that certain newer and differently configured products, such as UCS B-Series Blade Servers, UCS X-Series Modular Systems, and UCS C-Series M7 and M8 Rack Servers, remain unaffected by this flaw.<\/p>\n<p>Currently, no temporary workarounds or mitigations are available to block this vulnerability. The only effective solution is to <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cimc-auth-bypass-AgG2BxTn\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">apply the official software updates provided by Cisco.<\/a><\/p>\n<p>Administrators are strongly urged to immediately upgrade their affected systems to the fixed software releases.<\/p>\n<p>The update process varies by device; for instance, upgrading the IMC on 5000 Series ENCS and Catalyst 8300 Series requires upgrading the underlying Cisco Enterprise NFV Infrastructure Software (NFVIS).<\/p>\n<p>For standalone servers, administrators can typically use <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">the<a href=\"https:\/\/cybersecuritynews.com\/cisco-imc-vulnerability\/\" target=\"_blank\" rel=\"noopener\">\u00a0Cisco<\/a><\/span><a href=\"https:\/\/cybersecuritynews.com\/cisco-imc-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\"> Host Upgrade Utility (HUU) to install the fixed IMC releases.<\/a><\/p>\n<p>Cisco has credited a security researcher for reporting the flaw and noted that there is currently no evidence of active exploitation or public announcements regarding malicious use of this vulnerability.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisco-imc-vulnerability-2\/\">Critical Cisco IMC Vulnerability Let Attackers Bypass Authentication<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisco-imc-vulnerability-2\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical Cisco IMC Vulnerability Let Attackers Bypass Authentication Cisco has recently disclosed a critical security flaw affecting its Integrated Management Controller (IMC), prompting the release of urgent software updates. The vulnerability, officially tracked as CVE-2026-20093, has been assigned a critical Base CVSS score of 9.8, indicating the highest level of severity. This security weakness is [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1439,129,63,648],"tags":[130],"class_list":["post-11799","post","type-post","status-publish","format-standard","hentry","category-cisco","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11799"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11799"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11799\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11799"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11799"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11799"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}