Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)
PoC publicIntegrated Management Controller (IMC)Our summary
Cisco has issued a patch for a critical vulnerability, CVE-2026-20200, in its Integrated Management Controller (IMC), which enables authenticated remote attackers with low privileges to execute arbitrary commands as the root user. A proof-of-concept exploit named CIMCown is currently available on GitHub, confirming the immediate risk posed by this input validation flaw.
Affected systems include Cisco UCS C-Series M7 and M8 Rack Servers and various preconfigured Cisco appliances; administrators are advised to apply updates immediately. Since no workarounds exist besides disabling the web interface, securing management networks and isolating IMC from public exposure are critical mitigation steps.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.