securityonline.info 9 Sept 2026, 08:51 UTC

Cisco UCS Servers Face Secure Boot Bypass via Public Exploit

Cisco UCS Servers Face Secure Boot Bypass via Public Exploit
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CISCO has disclosed a high-severity vulnerability affecting its Unified Computing System (UCS) platform that enables a Secure Boot bypass via the UEFI shell. The flaw, tracked as CVE-2026-20293 with a CVSS v3 score of 7.1, could allow an authenticated user with basic access—or a threat actor with physical access—to execute unauthorised software on affected servers by manipulating in‑memory UEFI variables during boot.

Cisco notes that exploit code and full technical write‑ups are publicly available, although there have not been any reported cases of active exploitation at the time of the advisory.

The vulnerability resides in the UCS server UEFI Shell implementation. While Secure Boot is intended to load only signed code, the presence of memory write commands in the UEFI Shell when Secure Boot is enabled enables an attacker to modify memory variables and disable preboot security checks. The advisory states that an attacker could exploit this by selecting the UEFI Shell boot option and using available commands to alter memory, thereby bypassing Secure Boot on the hardware. Public proof-of-concept exploit code exists, and Cisco confirmed awareness of PoC availability, while noting no known malicious use at present.

Cisco lists multiple affected platforms, including Cisco UCS B-Series Blade Servers, C-Series Rack Servers, S-Series Storage Servers, X-Series Modular Systems, the 5000 Series Enterprise Network Compute Systems, and Unified Edge solutions, along with various appliances built on UCS hardware. The recommended mitigation is to deploy updated BIOS firmware, as Cisco has removed memory modification commands from the UEFI shell whenever Secure Boot is active.

Standalone C-Series systems should receive the latest Host Upgrade Utility, and appliance families should consult release tables for the designated firmware bundles.

View full article

Article by CyberSIXT