Full Breakdown
Cisco Addresses Critical Vulnerabilities in Integrated Management Controller and Smart Software Manager
4/3/2026, 2:21:36 AM
Overview of the Security Flaws
Cisco has announced the release of patches for two critical vulnerabilities affecting its Integrated Management Controller (IMC) and Smart Software Manager On-Prem (SSM On-Prem). The vulnerabilities, tracked as CVE-2026-20093 and CVE-2026-20160, both carry a CVSS score of 9.8, indicating their severity. These flaws could allow unauthenticated remote attackers to bypass authentication and execute arbitrary commands, respectively.
Details of the Vulnerabilities
The first vulnerability, CVE-2026-20093, is rooted in the incorrect handling of password change requests. An attacker could exploit this flaw by sending a crafted HTTP request to an affected device, allowing them to bypass authentication and alter user passwords, including those of administrators. This would enable the attacker to gain access to the system with elevated privileges.
The second critical flaw, CVE-2026-20160, affects the SSM On-Prem and stems from the unintentional exposure of an internal service. Attackers could exploit this vulnerability by sending a crafted request to the API of the exposed service, potentially executing commands on the underlying operating system with root-level privileges. Cisco stated that both vulnerabilities have not been exploited in the wild, although recent security flaws in Cisco products have been weaponized by threat actors.
Impacted Products
The vulnerabilities affect a range of Cisco products, including:
- 5000 Series Enterprise Network Compute Systems (ENCS)
- Catalyst 8300 Series Edge uCPE
- UCS C-Series M5 and M6 Rack Servers
- UCS E-Series Servers M3 and M6
Patches for these vulnerabilities have been released in various versions of the affected products, with specific updates noted for each.
Official Statements & Recommendations
Cisco has advised customers to update to the fixed versions of the affected products to ensure optimal protection. The company emphasized the importance of addressing these vulnerabilities promptly, given their potential for exploitation.
Criticism & Opposition
While Cisco has taken steps to address these vulnerabilities, some security experts have raised concerns about the frequency of critical flaws in their products. The ongoing discovery of vulnerabilities suggests a need for improved security practices within the company.
What's Next
Cisco continues to monitor the situation and has committed to providing further updates as necessary. Customers are encouraged to stay informed through Cisco's security advisories page for any additional information regarding these vulnerabilities and their resolutions.
Verbatim Quotes
- “An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service.” — Cisco
- “A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an Admin user, and gain access to the system as that user.” — Cisco
