[CIVN-2026-0402] Multiple Vulnerabilities in Cisco Integrated Management Controller

By Published On: August 11, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Cisco Integrated Management Controller


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Systems Affected


5000 Series Enterprise Network Compute Systems (ENCS)

Catalyst 8300 Series Edge uCPE

UCS C-Series M5 and M6 Rack Servers in standalone mode

UCS C-Series M7 and M8 Rack Servers in standalone mode

UCS E-Series Servers M3

UCS E-Series Servers M6

UCS S-Series Storage Servers in standalone mode

Overview


Multiple vulnerabilities exist in the Cisco Integrated Management Controller (IMC) which could allow an authenticated remote attacker to execute arbitrary commands on the affected system.


Target Audience:

All organizations and individuals using and maintaining CISCO products.


Risk Assessment:

High risk of arbitrary code execution on the underlying operating system.


Impact Assessment:

High impact on Confidentiality, Integrity and Availability of the system.


Description


Cisco Integrated Management Controller (IMC) is an embedded remote management controller for Cisco UCS servers, providing out-of-band administration and hardware management.


Multiple vulnerabilities exist in the web-based management interface of Cisco Integrated Management Controller due to improper validation of user-supplied input. An authenticated remote attacker could exploit these vulnerabilities by submitting crafted inputs to the web-based management interface of the affected software.


Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.


Solution


Apply appropriate security updates as mentioned by the vendor:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU



Vendor Information


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU


References


 

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU


CVE Name

CVE-2026-20288

CVE-2026-20200


– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp7J54ACgkQ3jCgcSdc

ys8ySA/+J9ZOkmTCKoOxpJWADSRSQOsJDUmGKK3gLvOJExyrRAu+gLySKF9Jm8Kp

sJGEOns85N63MF/MuUOfeut24pvEW3L1P49pD2U4uRkQWw1uEsYbn6s1CbzfnVnW

E+qxnSqcyoO13a3YrHAT960BiwhuU3IFIsa2bE4ts2Q92w6FM5zTsXZ8pGnQHekh

0b/7QHOu3C7LHgSs/740CCfdseMBUk8iuRAsDULmrh66Tuu6OzChZxRyWfVx6y32

mBZdjnLt/NFBhJAdJhyQUPalHMzBlr1Ac18REbCkHXkswzBVv2WkfW4lXLJsWoEw

pnqC6A73C8sIgKQELBn551IvphlH4p6IolJhnI46uNAJ2XfRQaGp4LYPwQvVrsKO

e+bykKBZ4g7lLMd/0CINb77xJjWik9718z4mpwux8aIwxAXuCAoQPTElgumskRUt

Zt/i/oadkmzWvkoy37ZQdecnFWi+egM2XpO4UyWb59nBFkP4o+aFeoPiyXCMioKB

zTXmgiAj0glEUReTdEh+YMZ61WbcQOnRRpj6brPGVkRIx5Yw8a3xx7f/5lJT4k86

sY0QAaiH+9dJ5ZyHRQU0KFVnAuyGFQkQP8cbh9Ncrw0l89pbqz8LVsS3fJgJXRUI

50uOlJHEtc7f0ZixawGcnG9BXuRyDvnFv8DTQ6JkkJ/eIuHsTYM=

=vCwR

—–END PGP SIGNATURE—–

Share this article