Cisco's server controller scored a 9.8 bug that hands out root — exploit code is already public

CVE-2026-20200 lets a low-privilege, already-logged-in attacker take full root control of Cisco UCS C-Series servers through the web management…

Aliteq
Ravi Malhotra · Hardware Editor

The short version

CVE-2026-20200 scores 9.8 out of 10 on CVSS and lets an authenticated, low-privilege attacker run commands as root on Cisco UCS C-Series M7/M8 servers.

The short version

The flaw is in the Integrated Management Controller (IMC) web interface — the tool that controls BIOS, SecureBoot, and remote power, sitting below the operating system.

The short version

Cisco shipped a fix in its August 5, 2026 advisory batch; the only stopgap besides patching is disabling the web interface entirely.

The short version

Discoverer Christoph Peil of NSIDE ATTACK LOGIC released a public proof-of-concept tool, CIMCown, on GitHub after the patch dropped.

The short version

Cisco says it has no evidence of exploitation in the wild yet — but a public PoC historically shortens that window fast.

The uncomfortable pattern

This is the third Cisco management-interface flaw serious enough to make our patch-now list in the past few months, after the SD-WAN and IOS XE bugs and the FMC zero-day. My honest read: Cisco's…

Aliteq

Read the full story

Cisco's server controller scored a 9.8 bug that hands out root — exploit code is already public

Read the full story on Aliteq