Threat reportVulnerabilityTL-2026-1912
Critical Cisco IMC Argument Injection (CVE-2026-20200) Enables Root RCE on UCS C-Series M7/M8 Standalone Servers — Public PoC (CIMCown)
Critical Cisco IMC Argument Injection (CVE-2026-20200) (TL-2026-1912), also tracked as CIMCown, is a critical-severity software vulnerability scored CVSS 8.8, first published 2026-08-06. It has no confirmed attribution, affects Cisco UCS C-Series M7 Rack Servers (standalone mode, Cisco IMC), references 2 CVEs (CVE-2026-20200, CVE-2026-20288), maps to 13 MITRE ATT&CK techniques (T1014, T1021, T1056), and is covered by 9 detection rules and 9 indicators of compromise.
- CVSS
- 8.8/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 13MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 9Indicators of compromise
Key facts for TL-2026-1912
- Threat ID
- TL-2026-1912
- Also known as
- CIMCown, Cisco IMC Argument Injection
- Severity
- CRITICAL
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- datacenter, enterprise, telecoms, government administration, cloudserviceprovider, health
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 9
Malware and tooling in Critical Cisco IMC Argument Injection (CVE-2026-20200)
Malware and tooling: CIMCown
How Critical Cisco IMC Argument Injection (CVE-2026-20200) works
CVE-2026-20200 is a critical argument injection vulnerability in the web-based management interface of the Cisco Integrated Management Controller (IMC), the out-of-band BMC on UCS C-Series M7/M8 rack servers and S-Series storage servers. An authenticated remote attacker with only low/read-only privileges can execute arbitrary commands on the underlying OS as root by injecting extra curl flags into the SSH-key-import feature. A public proof-of-concept toolkit (CIMCown) is available; no workaround exists.
CVE-2026-20200 is an argument injection (CWE-141 / CWE-146) vulnerability in the web-based management interface of the Cisco Integrated Management Controller (IMC), the baseboard management controller (BMC) that provides out-of-band management for Cisco UCS C-Series rack servers and S-Series storage servers. The flaw, discovered by Christoph Peil of NSIDE ATTACK LOGIC during a commissioned security assessment, stems from improper validation of user-supplied input. An authenticated, remote attacker holding only low-privilege (e.g., read-only) credentials can enter crafted input to the web UI and execute arbitrary commands on the underlying IMC operating system as root, fully escalating privileges. Cisco assigned CVSS 8.8 (High SIR); NSIDE assesses 9.9 with a changed-scope vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). The hunt skeleton and media coverage cite a 9.8 critical rating, reflecting the severity of self-hosted UCS exposure.
The root cause is a shell-script argument injection in the IMC's SSH key import functionality. When a user requests that the IMC fetch an SSH public key from a remote server over HTTP or FTP, the backend invokes a script effectively equivalent to `/etc/scripts/download_ssh_keys.sh http <host> <destination>`, which forwards user-controlled parameters directly to the curl binary. Because the script and curl execute with root privileges, an attacker can inject additional curl flags (for example `-o` to write arbitrary files, `--upload-file` to exfiltrate files, or `-K` to read files as curl config) to achieve arbitrary file read, file write, and — via loading a crafted library — full command execution as root.
The NSIDE-released CIMCown toolkit operationalizes this. It connects to a low-privilege account on the IMC web/API interface, and supports (1) `test` — downloads `/etc/passwd` as a connectivity check, (2) `download` — retrieves any remote file from the IMC, (3) `upload` — writes a file to an arbitrary remote path, (4) `build` — compiles a Go-based reverse shell for the IMC's ARM architecture, and (5) `shell` — deploys and executes the reverse shell against an attacker listener. The exploit drops a shared library (`lib.so`) and a compiled Go reverse shell binary into `/tmp/main` on the IMC, and supports HTTP proxy routing (`--proxy`).
The IMC occupies a privileged architectural position that makes root compromise especially damaging. As an out-of-band BMC it runs its own management OS with dedicated RAM and network interface, independent of the host OS. Root access to the IMC lets an attacker influence BIOS/UEFI and SecureBoot settings, interact directly with running host OS instances, power-cycle servers, and persist below the operating system — far below what OS-level EDR and endpoint defenses can observe. NSIDE describes the IMC as 'an operating system for the operating system.' Cisco stated it was not aware of malicious exploitation at the time of publication but confirmed proof-of-concept exploit code is publicly available.
This advisory (cisco-sa-cimc-arg-inject-upSHdMfU) also discloses a companion vulnerability, CVE-2026-20288, an admin-privilege argument injection (CVSS 6.5) affecting a broader set of platforms including UCS C-Series M5/M6, S-Series storage servers, 5000 Series ENCS, Catalyst 8300 uCPE, and UCS E-Series. CVE-2026-20200 specifically affects UCS C-Series M7 and M8 standalone rack servers. The vulnerability follows the historical pattern of CVE-2024-20356 (CISCown, LRQA Nettitude), a curl-command-injection in Cisco CIMC firmware-update functionality, evidencing a systemic weakness in how IMC passes user input to curl. It is part of a wider 2026 wave of IMC vulnerabilities including CVE-2026-20093 (unauthenticated auth bypass, CVSS 9.8) and CVE-2026-20094 (read-only command injection, CVSS 8.8). No workarounds are available; the only remediation is upgrading IMC firmware to fixed releases.
MITRE ATT&CK techniques used in TL-2026-1912
Defense Evasion
T1014 Rootkit; T1542 Pre-OS Boot
Lateral Movement
Collection
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Discovery
T1082 System Information Discovery
Impact
T1490 Inhibit System Recovery; T1529 System Shutdown/Reboot
Credential Access
Command and Control
defense-impairment
Affected products and versions in Critical Cisco IMC Argument Injection (CVE-2026-20200)
- Cisco — UCS C-Series M7 Rack Servers (standalone mode, Cisco IMC)
Vulnerable versions: 4.3.x; 6.0(1.250127); 6.0(1.250131); 6.0(1.250174); 6.0(1.250130); 6.0(1.250192); 6.0(1.250194)
Fixed in: 4.3(6.260033); 6.0(2.260044) - Cisco — UCS C-Series M8 Rack Servers (standalone mode, Cisco IMC)
Vulnerable versions: 4.3.x; 6.0.1.x
Fixed in: 4.3(6.260033); 6.0(2.260044) - Cisco — UCS C-Series M5/M6 Rack Servers (standalone mode) — CVE-2026-20288 only
Vulnerable versions: 4.2 and earlier; 4.3.x; 6.0.x
Fixed in: 4.2(3r); 4.3(6.260054); 6.0(2.260143) - Cisco — UCS S-Series Storage Servers (standalone mode) — CVE-2026-20288 only
Vulnerable versions: 4.3.x
Fixed in: 4.3(6.260054) - Cisco — 5000 Series ENCS / Catalyst 8300 Series Edge uCPE — CVE-2026-20288 only
Vulnerable versions: NFVIS 4.12, 4.13-4.16, 4.18, 26.1
Fixed in: 4.12.8; 4.15.6; 4.18.5; 26.1.2 - Cisco — UCS E-Series M3/M6 Servers — CVE-2026-20288 only
Vulnerable versions: 3.2 and earlier; 4.15 and earlier
Fixed in: 3.2.18.1; 4.15.4 - Cisco — Appliances built on UCS C-Series hardware (APIC, Catalyst Center, Expressway, HyperFlex, Nexus Dashboard, Secure Firewall Management Center, Secure Endpoint, Secure Network Analytics, ISE SNS, etc.)
Vulnerable versions: expose IMC UI
Fixed in: per-platform fixed firmware/HUU
Remediation for Critical Cisco IMC Argument Injection (CVE-2026-20200)
Patches
- Cisco IMC 4.3 branch: upgrade to 4.3(6.260033) or later (fixes CVE-2026-20200)
- Cisco IMC 6.0 branch: upgrade to 6.0(2.260044) or later (fixes CVE-2026-20200)
- Releases earlier than 4.3: migrate to a fixed release
- For CVE-2026-20288 (admin argument injection): 4.3(6.260054) and 6.0(2.260143) across affected M5/M6/M7/M8/E-Series/S-Series/ENCS/uCPE platforms
Immediate actions
- Temporarily disable the IMC web-based management interface on all UCS C-Series M7/M8 standalone servers to block the primary attack vector
- Restrict network access to IMC management interfaces to trusted jump hosts on a strictly segmented management network; never expose IMC to the internet
- Audit all IMC user accounts and remove or disable any unnecessary low-privilege / read-only accounts that could be chained to root
- Review IMC web UI access logs for anomalous SSH-key-import operations, unexpected curl invocations, or file-download/upload patterns
Workarounds
- Disable the IMC web UI entirely to block the attack path (per NSIDE ATTACK LOGIC)
- Ensure IMC interfaces are not exposed to internal or public networks; use strictly segmented management networks
- Restrict who holds any IMC account, since low-privilege (even read-only) access is sufficient
Longer-term hardening
- Upgrade IMC firmware to fixed releases: 4.3(6.260033) or 6.0(2.260044) for M7/M8 standalone servers
- Treat out-of-band management interfaces (BMC/IMC) as Tier-0 assets per CISA/NSA guidance and enforce strict network segmentation with firewall-only access
- Adopt a least-privilege model for all IMC user accounts and implement restrictive role-based access control
- Enable centralized, immutable logging and monitoring of IMC administrative actions and firmware changes
- Establish a patch-management cadence for server management controller firmware, not just the host OS
CVEs associated with Critical Cisco IMC Argument Injection (CVE-2026-20200)
CVE-2026-20200, CVE-2026-20288
Weaknesses (CWE) in Critical Cisco IMC Argument Injection (CVE-2026-20200)
Timeline of Critical Cisco IMC Argument Injection (CVE-2026-20200)
- CVE-2024-20356 disclosed: CISCown (LRQA Nettitude) demonstrated curl-command-injection-to-root in Cisco CIMC firmware update functionality, establishing the curl-injection attack pattern later exploited in CVE-2026-20200
- Cisco publishes IMC advisory cisco-sa-cimc-auth-bypass-AgG2BxTn covering CVE-2026-20093, a critical unauthenticated authentication bypass (CVSS 9.8) in the IMC password-change function
- Cisco publishes IMC advisory cisco-sa-cimc-cmd-inj-3hKN3bVt covering CVE-2026-20094 (read-only command injection, CVSS 8.8) among other IMC command-injection/RCE flaws
- Cisco confirms no workarounds exist, requires firmware upgrade to 4.3(6.260033) or 6.0(2.260044); states no known malicious exploitation at publication time but acknowledges public PoC availability
- NSIDE ATTACK LOGIC publishes research write-up 'Cisco IMC — When remote management becomes a backdoor' detailing the curl argument-injection mechanism and impact of IMC root compromise
- NSIDE ATTACK LOGIC releases CIMCown public proof-of-concept exploit on GitHub demonstrating root-level RCE against Cisco IMC via the SSH-key-import argument injection
- CVE-2026-20200 and companion CVE-2026-20288 published by Cisco in advisory cisco-sa-cimc-arg-inject-upSHdMfU; vulnerability discovered by Christoph Peil of NSIDE ATTACK LOGIC during a commissioned assessment
- Help Net Security and other outlets report the critical Cisco IMC vulnerability and public PoC, emphasizing the below-OS attack surface on UCS standalone servers
- NVD publishes CVE-2026-20200 and CVE-2026-20288 records; CISA SSVC lists exploitation as 'none' with technical impact 'total'
Sources cited for Critical Cisco IMC Argument Injection (CVE-2026-20200)
- Cisco Security Advisory: Cisco Integrated Management Controller Command Injection Vulnerability (cisco-sa-cimc-arg-inject-upSHdMfU)
- CIMCown public proof-of-concept exploit (NSIDE ATTACK LOGIC)
- Researcher write-up: Cisco IMC — When remote management becomes a backdoor (CVE-2026-20200)
- Help Net Security: Critical Cisco IMC command injection gives root on UCS servers, public PoC available
- NVD: CVE-2026-20200
- NVD: CVE-2026-20288
- Cisco Security Advisory: Cisco IMC Command Injection and Remote Code Execution (cisco-sa-cimc-cmd-inj-3hKN3bVt)
- Cisco Security Advisory: Cisco IMC Authentication Bypass (cisco-sa-cimc-auth-bypass-AgG2BxTn)
- NSIDE-SA-2026-003 / NSIDE ATTACK LOGIC advisory
- CVE-2024-20356 CISCown (LRQA Nettitude) — historical CIMC curl command injection
Detection coverage for TL-2026-1912
As of 2026-08-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1912 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.