Back to feed

Cisco fixes critical IMC flaw giving attackers root, PoC published

1 min
Cisco fixes critical IMC flaw giving attackers root, PoC published

This digest was compiled by AI from multiple sources — links to the originals are below.

Cisco has patched a critical vulnerability in its Integrated Management Controller (IMC) that allows authenticated attackers to execute commands as root via the web interface. A proof-of-concept exploit for the flaw, tracked as CVE-2026-20200, has been published. The fix was among several advisories released August 5, including hardening releases for IOS XE and Catalyst SD-WAN flaws uncovered with the help of AI.

The IMC Exploit

Cisco Integrated Management Controller (IMC) is used to manage UCS C-Series rack servers and S-Series storage servers. The vulnerability, CVE-2026-20200, has a CVSS score of 9.8 and stems from improper input validation in the web interface. A remote authenticated attacker with low privileges can send crafted inputs to execute arbitrary commands as root. Researcher Christoph Peil of German firm NSIDE ATTACK LOGIC discovered the flaw during a commissioned assessment and published a proof-of-concept exploit, CIMCown, on GitHub.

AI-Discovered Flaws

Cisco also released hardening updates for IOS XE and Catalyst SD-WAN, addressing multiple critical vulnerabilities discovered through internal testing aided by frontier AI models. The IOS XE advisory covers seven Common Weakness Enumeration (CWE) classes, with command injection flaws (CVE-2026-20272) rated 9.8. The SD-WAN advisory addresses five CWE classes, including improper input validation and access-control bypass, all rated 9.9. The company grouped vulnerabilities by underlying CWE category and assigned one CVE per group.

1 source

Time · lag behind first