securityaffairs.com 4/2/2026, 5:52:58 PM · via preferred

Cisco fixed critical and high-severity flaws

Cisco fixed critical and high-severity flaws

CVE-2026-20093: Critical Cisco IMC Flaw Allows Unauthenticated Admin Access to UCS Servers

CVE-2026-20093 is described as a critical authentication bypass flaw in Cisco IMC that could allow an unauthenticated remote attacker to bypass authentication and gain full administrative access to UCS servers. The vulnerability carries a CVSS score of 9.8 and stems from improper input validation in the password change functionality of IMC, enabling an…

First seen 2026-04-02T12:51:11.870Z · Last seen 2026-04-03T09:33:21.389Z

CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
Interlock

CISCO released patches for two critical and six high-severity vulnerabilities that could allow attackers to bypass authentication, run code, escalate privileges, and access sensitive data. One of the critical flaws, CVE-2026-20093, affects Cisco IMC and could let a remote attacker bypass authentication via a crafted HTTP request, potentially allowing changes to user passwords including admin and full system access, with a CVSS score of 9.8.

Another critical issue, CVE-2026-20160, affects SSM On-Prem and could enable unauthenticated attackers to run commands on the host OS with root privileges through a crafted API request, also rated 9.8. In March, Cisco fixed a critical RCE zero-day, CVE-2026-20131, in Secure Firewall FMC, which Interlock ransomware reportedly exploited, and US CISA added the flaw to its Known Exploited Vulnerabilities catalog. Cisco’s PSIRT says there are no known exploits or PoCs at present, and it strongly advises customers to update to the patched software.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline