arstechnica.com 8/5/2026, 11:21:33 PM · external

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Thousands of servers can be backdoored by exploiting buggy motherboard controllers
CyberSIXT Evidence Panel
Primary Source cisa.gov

RESEARCH revealed that critical vulnerabilities in baseboard management controllers (BMCs)—integral components of enterprise servers sold by major manufacturers—can allow hackers to remotely backdoor thousands of servers. These vulnerabilities, some over a decade old, enable attackers to execute malicious code, manage assets, and exploit connections even when the servers are off.

The findings, presented at the Black Hat conference, showed that scans of BMCs found over 86,000 devices publicly exposed, with 54% containing critical vulnerabilities. Prevalent issues include flaws in IPMI authentication, session hijacking risks due to predictable identifiers, and recovery of sensitive information from firmware. Despite existing patches, many devices remain vulnerable, making BMCs a significant and under-assessed cybersecurity risk.

View Primary Source Via arstechnica.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline