【Vulnerability Alert】Cisco Integrated Management Controller Contains a Critical Cybersecurity Vulnerability (CVE-2026-20200)
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026080605085151 | Publication Time | 2026-08-06 17:17:53 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-08-06 17:17:53 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Cisco Integrated Management Controller Contains a Critical Cybersecurity Vulnerability (CVE-2026-20200) |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000003 Cisco Integrated Management Controller (IMC) is a management tool specifically designed for servers in Cisco Unified Computing System, providing remote server monitoring, configuration, and management functions. Recently, Cisco issued a critical cybersecurity advisory (CVE-2026-20200, CVSS: 8.8). This vulnerability may allow an authenticated remote attacker to execute arbitrary code or commands on the affected underlying operating system and elevate privileges to root. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
UCS C-Series M7 and M8 Rack Servers in standalone mode |
|||
|
[Recommended Actions] Apply the patch according to the remediation instructions released on the official website: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU |
|||
|
[Reference] 1. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





