CVE Tools

Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)

Help Net SecurityBy Zeljka Zorz

PoC publicIntegrated Management Controller (IMC)

Our summary

Cisco has issued a patch for a critical vulnerability, CVE-2026-20200, in its Integrated Management Controller (IMC), which enables authenticated remote attackers with low privileges to execute arbitrary commands as the root user. A proof-of-concept exploit named CIMCown is currently available on GitHub, confirming the immediate risk posed by this input validation flaw.

Affected systems include Cisco UCS C-Series M7 and M8 Rack Servers and various preconfigured Cisco appliances; administrators are advised to apply updates immediately. Since no workarounds exist besides disabling the web interface, securing management networks and isolating IMC from public exposure are critical mitigation steps.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store