By Zeljka Zorz
Publication Date: 2026-08-06 10:38:00
Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s web interface.
The fix was part of Cisco’s August 5 advisory batch, and unlike the bugs squashed by the hardening releases for IOS XE and SD-WAN, this one has a public proof-of-concept exploit.
AI-discovered flaws in IOS XE and SD-WAN
Cisco made available hardening releases addressing critical-severity flaws in Cisco IOS XE and Cisco Catalyst SD-WAN, which power its enterprise networking hardware.
Rather than issue a separate advisory per flaw, Cisco grouped the vulnerabilities by their underlying Common Weakness Enumeration (CWE) category and assigned one CVE identifier per group.
The SD-WAN advisory rolls up five CVE classes, led by improper input validation, access-control bypass, and improper link resolution, all rated 9.9.
IOS XE covers seven classes, with a…

