Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200) – Help Net Security

Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200) – Help Net Security

By Zeljka Zorz
Publication Date: 2026-08-06 10:38:00

Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s web interface.

The fix was part of Cisco’s August 5 advisory batch, and unlike the bugs squashed by the hardening releases for IOS XE and SD-WAN, this one has a public proof-of-concept exploit.

AI-discovered flaws in IOS XE and SD-WAN

Cisco made available hardening releases addressing critical-severity flaws in Cisco IOS XE and Cisco Catalyst SD-WAN, which power its enterprise networking hardware.

Rather than issue a separate advisory per flaw, Cisco grouped the vulnerabilities by their underlying Common Weakness Enumeration (CWE) category and assigned one CVE identifier per group.

The SD-WAN advisory rolls up five CVE classes, led by improper input validation, access-control bypass, and improper link resolution, all rated 9.9.

IOS XE covers seven classes, with a…