Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability

Cisco IMC authentication bypass exposure

Updated 02.04.2026 14:01
Case score 60
Members 1 First seen 02.04.2026 14:01 Latest activity 02.04.2026 14:01

Overview

Cisco released security updates for **Cisco IMC/CIMC** after finding **CVE-2026-20093**, a password-change authentication bypass on **UCS C-Series and E-Series servers**. An unauthenticated attacker can send a crafted HTTP request to the management interface and reach **Admin** access if the device is unpatched. Cisco says there are **no workarounds** and recommends upgrading to the fixed software as soon as possible. Available evidence does not show in-the-wild exploitation or proof-of-concept code.
Latest development

Cisco IMC password change authentication bypass disclosed

Cisco released security updates on 2026-04-02 for Cisco IMC/CIMC after finding CVE-2026-20093 in the password change functionality. An unauthenticated attacker can send a crafted HTTP request to an affected UCS C-Series or E-Series server, bypass authentication, alter user passwords including an Admin account, and gain Admin privileges on the management controller. Cisco said there are no workarounds and strongly recommended upgrading to the fixed software, while PSIRT had not found in-the-wild exploitation or proof-of-concept exploit code.

Signals

Exploitation
CVEs/products
Remediation
Data exposure

Threat actor context

1 listed

Technical intelligence

Existing Case data

Member happenings

Vulnerability Cisco IMC password change authentication bypass (CVE-2026-20093)
Updated 02.04.2026 14:01 Lead Contribution 60
Exploitation No Known Exploitation Exploit No Known Public Exploit Data Type Passwords Patch Patch Available

Cisco released **security updates** for **Cisco IMC/CIMC** after a **password-change authentication bypass** was found that lets **unauthenticated attackers** gain **Admin access** on affected **UCS C-Series and E-Series servers**. Tracked as **CVE-2026-20093**, the flaw can be triggered with a **crafted HTTP request** against the IMC password-change path. Cisco says there are **no workarounds** and recommends upgrading to the **fixed software** as soon as possible. The company has not found **in-the-wild exploitation** or **proof-of-concept exploit code**.