CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-20200: Cisco IMC Command Injection

August 6, 2026

CVE-2026-20200 is a high-severity vulnerability in the Cisco Integrated Management Controller (IMC) with a CVSS score of 8.8. It allows an authenticated remote attacker with low privileges to execute arbitrary commands and elevate to root. A proof-of-concept exploit is available. Cisco has released fixes.