Cisco has patched a critical vulnerability in its Integrated Management Controller that lets low-privileged, authenticated attackers execute commands as root, and a public proof-of-concept is already circulating.
The flaw, tracked as CVE-2026-20200, sits in the web-based management interface of Cisco IMC, the controller used to manage UCS C-Series rack servers and S-Series storage servers, even when their operating systems are down. It stems from improper validation of user-supplied input and carries a CVSS score of 9.8.
German researcher Christoph Peil of NSIDE ATTACK LOGIC found the bug during a commissioned assessment. Cisco shipped the patch in its August 5 security update, bundled alongside hardening releases for IOS XE and Catalyst SD-WAN.
Those releases address critical-severity flaws found with the help of frontier AI models and grouped by weakness category: the SD-WAN advisory rolls up five CVE classes led by input validation and access-control bypass issues rated 9.9, while IOS XE covers seven classes topped by a command injection group at 9.8. Cisco says it has no evidence these networking flaws were publicly disclosed or exploited, and no workarounds exist.
The IMC bug is the urgent one. Admins managing UCS and S-Series hardware should apply the fixed IMC release immediately, and because a working exploit is public, any exposed management interface should be treated as a real risk until patched.
