Threat Advisory

Cisco IMC Flaw Lets Attackers Execute Arbitrary Commands

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Cisco Integrated Management Controller (IMC) web-based management interface...

CVE-2026-20200 (CVSS 8.8 — High): An authenticated, remote attacker can execute arbitrary commands on the underlying operating system and elevate privileges to root.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Cisco Integrated Management Controller (IMC) web-based management interface...

CVE-2026-20200 (CVSS 8.8 — High): An authenticated, remote attacker can execute arbitrary commands on the underlying operating system and elevate privileges to root.[emaillocker id="1283"]

CVE-2026-20288 (CVSS 8.8 — High): An authenticated, remote attacker can execute arbitrary commands on the underlying operating system and elevate privileges to root. These vulnerabilities collectively present a significant risk to administrators who have not applied updates, particularly those with direct access to the web-based management interface. These vulnerabilities collectively present a significant risk to administrators who have not applied updates, particularly those with direct access to the web-based management interface.

These vulnerabilities collectively present a significant risk to administrators who have not applied updates, particularly those with direct access to the web-based management interface.

RECOMMENDATION:

We recommend you to update Cisco IMC to given version link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Integrated%20Management%20Controller%20Argument%20Injection%20Vulnerabilities%26vs_k=1

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu