CVE-2026-20293
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
Public exploit available. Not confirmed exploited in the wild yet. No fix published yet.
What to do
No fixed build or workaround is published yet. Limit exposure and watch for a patch.
Steps
Written by AI from the record- Confirm whether your environment uses one of these products: cisco enterprise nfv infrastructure software, cisco unified computing system (managed), cisco unified computing system (standalone), cisco unified computing system e-series software (ucse).
- Check whether UEFI Secure Boot is enabled on the affected servers/appliances (the bypass is possible when Secure Boot is enabled).
- Assess whether anyone outside trusted staff can reach the local console/boot menu or obtain physical control of the device (the attack requires local/physical access to select the UEFI Shell boot option).
- If you have any realistic risk of local/physical access, immediately tighten access controls: restrict console access, add physical security, and prevent booting into the UEFI Shell wherever your management interface/firmware policy allows.
- Contact Cisco support or your vendor/managed service provider to obtain the official guidance and confirm whether a firmware update exists for CVE-2026-20293; no fix information is available from the provided findings.
- If a fix is not yet available, prioritize compensating controls (strong physical security, strict console/boot policy, and tighter administrative access) and document a risk acceptance decision until a patch is released.
What it is
From the CVE record
A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software. This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device.
In plain language
Written by AI from the recordCVE-2026-20293 is a Cisco server/appliance UEFI firmware flaw that lets someone with local console or physical access bypass Secure Boot and run software before your system starts—this is a serious concern if you have any chance of unattended physical access or high-risk console access.
CVE-2026-20293 is a UEFI Shell Secure Boot bypass (CWE-749) on Cisco UCS and UCS-based appliances, where an attacker who can reach the UEFI Shell at boot (via local console/physical access, and sometimes with low-privilege credentials) can modify Secure Boot-related settings to execute unauthorized pre-boot software.
If you're affected
- Full pre-OS compromise
- Bypass Secure Boot protections
- Unauthorized software execution
- Potential ransomware staging
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Not in the catalog. CISA has not confirmed exploitation.
- Public exploits
0 sources with a proof of concept or module.
Exploit links, PoCs and Metasploit modules after sign-in- EPSS
0.2% chance of exploitation activity in the next 30 days, which ranks it in the 4th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
- Attention now
Rising, driven by in-the-wild reports.
Lifecycle
5 events over 3 days, from the signal feeds we watch.
- OpenVAS check addedrecord updated
- Publishedweakness classified, record updated
Affected products
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Scored 7.1 by NVD.
How it is reached
- Attack Vector LocalRequires local access to the vulnerable system (e.g. local login, malicious file)
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required LowRequires basic user-level privileges
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity HighTotal loss of integrity — attacker can modify any data in the component
- Availability NoneNo availability impact
Weaknesses
Sources
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Cisco, not every advisory. This one: public exploit.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI