TL;DR
Cisco disclosed two Cisco IMC vulnerabilities in the web-based management interface. The more serious one, CVE-2026-20200, scores 8.8 and allows root-level remote code execution. Cisco confirms that proof-of-concept exploit code is publicly available for it.
- Product: Cisco Unified Computing System (Standalone)
- Vulnerabilities: 2 flaws (CVE-2026-20200, CVE-2026-20288)
- Highest severity: 8.8 (High · CVSSv3)
- Worst impact: Integrated Management Controller Argument Injection and Remote Code Execution
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-20200 | 8.8 | CWE-141 | — | Not exploited |
| CVE-2026-20288 | 6.5 | CWE-146 | — | Not exploited |
Why it matters
The IMC manages Cisco servers at a low level. A root compromise there gives deep control of the hardware. Per Cisco, the flaws could let an attacker “execute arbitrary commands on the underlying operating system” and “elevate privileges to root.”
How the attacks work
Both flaws sit in the IMC web interface. Each needs an authenticated, remote attacker. However, the two issues are independent. One does not require the other to work.
CVE-2026-20200 is an argument injection and RCE flaw. It scores 8.8 and needs only low privileges. CVE-2026-20288 is a separate RCE issue rated 6.5, but it requires high privileges. This report withholds working exploit steps.
Public disclosure and exploit code
Cisco states plainly that “proof-of-concept exploit code is available for CVE-2026-20200.” That public availability raises the urgency for defenders.
Exploitation status
Public proof-of-concept code exists for CVE-2026-20200. However, Cisco “is not aware of any malicious use” of these flaws at this time.
Affected versions
The flaws affect devices running a vulnerable release of Cisco IMC. That includes the 5000 Series ENCS, UCS E-Series, and other UCS-based standalone systems.
Patch and mitigation
There are no workarounds. Cisco urges customers to upgrade to a fixed software release. Apply the vendor updates as soon as possible.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.