Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)

Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s web interface.

The fix was part of Cisco’s August 5 advisory batch, and unlike the bugs squashed by the hardening releases for IOS XE and SD-WAN, this one has a public proof-of-concept exploit.

AI-discovered flaws in IOS XE and SD-WAN

Cisco made available hardening releases addressing critical-severity flaws in Cisco IOS XE and Cisco Catalyst SD-WAN, which power its enterprise networking hardware.

Rather than issue a separate advisory per flaw, Cisco grouped the vulnerabilities by their underlying Common Weakness Enumeration (CWE) category and assigned one CVE identifier per group.

The SD-WAN advisory rolls up five CVE classes, led by improper input validation, access-control bypass, and improper link resolution, all rated 9.9.

IOS XE covers seven classes, with a command/OS/argument-injection group (CVE-2026-20272) the most severe at 9.8.

The vulnerabilities were discovered internally, through existing testing processes and with the help of frontier AI models.

The company says it has no awareness of public disclosure or malicious exploitation of these issues at the time of publication.

No workarounds have been provided. Customers are urged to upgrade devices running affected IOS XE or Catalyst SD-WAN releases to the fixed releases listed in each advisory. Cisco-managed SD-WAN cloud instances were patched automatically.

The IMC flaw (CVE-2026-20200)

The most urgent item in Cisco’s August 5 security batch isn’t one of the AI-discovered flaws in its networking software, though.

Cisco also fixed CVE-2026-20200, a vulnerability in Cisco Integrated Management Controller (Cisco IMC), the system that data center technicians and admins use to manage Cisco UCS C-Series rack servers and S-Series storage servers (even when their OS is not responding).

CVE-2026-20200 affects the web-based management interface of Cisco IMC, and is due to improper validation of user-supplied input.

“An [authenticated, remote attacker with low privileges] could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user,” Cisco explained in the advisory.

The vulnerability was discovered by Christoph Peil of German security firm NSIDE ATTACK LOGIC, druing a commissioned assessment, and carries a CVSS score of 9.8.

Following Cisco’s security releases, the researcher published a proof-of-concept exploit dubbed CIMCown on GitHub.

“One should be clear about what a compromise of the IMC means: the controller sits in a position where it can influence the BIOS and SecureBoot and interact with the operating system above it. An attacker who gains root here can thereby nest themselves deeply and persistently in the system – far below what classic protective measures such as EDR solutions at the operating-system level can even see,” Peil noted.

“The IMC can update the BIOS, configure SecureBoot, and thereby interact directly with the operating systems running on the server. In that sense, an operating system for the operating system. If an attacker gets in here, they effectively control the server and all the systems running on it.”

Cisco says there are no workarounds to address this vulnerability. Updating vulnerable products – UCS C-Series M7 and M8 Rack Servers in standalone mode, but also a myriad of Cisco appliances that are based on a preconfigured version of one of the Cisco UCS C-Series Servers – is advised.

“If an update is not possible at short notice, we recommend completely disabling the web interface (web UI) in order to block the affected attack path,” Peil advised.

“Beyond that, the following applies to management controllers as well as the Cisco IMC in general: such interfaces should never be exposed openly to the internal and especially a public network. A strictly segmented, separate management network, restrictive access controls, and a clean rights-and-roles concept significantly reduce the attack surface – and ensure that a single vulnerability does not immediately endanger the entire data center.”

source: HelpNetSecurity