As cited
Copy frozen at (site build).
vulnerabilities
Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)
Cisco patched a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller that enables remote attackers to execute commands with root privileges through the web interface. The fix arrived in Cisco's August 5, 2026 advisory, and a public proof-of-concept exploit has been released for this flaw. Hardening releases also addressed critical flaws in IOS XE and SD-WAN platforms.
Why it matters: Organizations running Cisco IMC are at immediate risk of privilege escalation and complete system compromise; apply the August 5 patch without delay given the availability of working exploit code.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)
Cisco patched a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller that enables remote attackers to execute commands with root privileges through the web interface. The fix arrived in Cisco's August 5, 2026 advisory, and a public proof-of-concept exploit has been released for this flaw. Hardening releases also addressed critical flaws in IOS XE and SD-WAN platforms.
Why it matters: Organizations running Cisco IMC are at immediate risk of privilege escalation and complete system compromise; apply the August 5 patch without delay given the availability of working exploit code.
- Source published
- First seen by Cybersecurity Tracker