CISCO has disclosed two critical vulnerabilities affecting its IMC (Integrated Management Controller) web interface: CVE-2026-20200 and CVE-2026-20288. The more severe CVE-2026-20200 allows root-level remote code execution (RCE) with a CVSS score of 8.8, while CVE-2026-20288 has a score of 6.5 and requires higher privileges. Both issues necessitate authenticated remote access but are independent of each other.
Cisco reports that there is public proof-of-concept exploit code available for CVE-2026-20200, though no malicious exploitation has been observed. The vulnerabilities affect specific Cisco models, and users are urged to update their software as no workarounds are available.