Date Posted: 2026/08/07
【Vulnerability Alert】Critical Security Vulnerability in Cisco Integrated Management Controller (CVE-2026-20200)
- Subject: 【Vulnerability Alert】Critical Security Vulnerability in Cisco Integrated Management Controller (CVE-2026-20200)
- Description:
- Forwarded Security Alert from TWCERT/CC (Taiwan Computer Emergency Response Team/Coordination Center) TWCERTCC-200-202608-00000003
- Cisco Integrated Management Controller (IMC) is a management tool specifically designed for Cisco Unified Computing System (UCS) servers, providing remote server monitoring, configuration, and management capabilities. Cisco recently released a critical security advisory (CVE-2026-20200, CVSS: 8.8). This vulnerability allows an authenticated remote attacker to execute arbitrary code or commands on the underlying affected operating system and elevate privileges to root.
- Affected Platforms:
- UCS C-Series M7 and M8 Rack Servers in standalone mode
- Recommendations:
- Apply patches according to the solution provided on the official website: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU
- Reference Information:
Computer and Communication Center
Network Systems Division