Root command execution via Cisco IMC web UI; widely deployed in data centers; could disrupt IT ops.
CVE-2026-20094
Authenticated read-only user can inject commands via Cisco IMC web UI and gain root.
Is CVE-2026-20094 being exploited?
Not confirmed. CVE-2026-20094 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 1.1% probability of exploitation in the next 30 days.
How severe is CVE-2026-20094?
CVE-2026-20094 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-20094?
Yes. A fix has been recorded for CVE-2026-20094. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-20094 affect?
CVE-2026-20094 affects Cisco Integrated Management Controller (IMC), Cisco UCS servers with IMC. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-20094?
Patch IMC; restrict UI access; monitor for anomalous activity.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Authenticated read-only user can inject OS commands via IMC web UI, escalating to root.
Immediate action required
- affected3.2.7
- affected3.2.6
- affected3.2.4
- affected3.2.10
- affected3.2.2
- affected3.2.3
- affected2.4.0
- affected3.2.1
- affected3.2.11.1
- affected3.2.8
- affected3.1.1
- affected3.0.2
- affected2.1.0
- affected2.2.2
- affected3.1.2
- affected3.0.1
- affected2.3.2
- affected2.3.5
- affected2.2.1
- affected3.1.4
- affected2.4.1
- affected2.3.1
- affected3.1.3
- affected2.3.3
- affected2.4.2
- affected3.1.5
- affected3.1.0
- affected2.0.0
- affected3.2.11.3
- affected3.2.11.5
- affected3.2.12.2
- affected3.2.13.6
- affected3.2.14
- affected4.11.1
- affected3.2.15
- affected4.12.1
- affected3.2.15.3
- affected4.12.2
- affected3.2.16.1
- affected4.00
- affected4.15.2
- affected4.02
- affected4.0(2g)
- affected3.1(2i)
- affected3.1(1d)
- affected4.0(4i)
- affected4.1(1c)
- affected4.0(2c)
- affected4.0(1e)
- affected4.0(2h)
- affected4.0(4h)
- affected4.0(1h)
- affected4.0(2l)
- affected3.1(3g)
- affected4.0(1.240)
- affected4.0(2f)
- affected4.0(1g)
- affected4.0(2i)
- affected3.1(3i)
- affected4.0(4d)
- affected4.1(1d)
- affected3.1(3c)
- affected4.0(4k)
- affected3.1(2d)
- affected3.1(3a)
- affected3.1(3j)
- affected4.0(2d)
- affected4.1(1f)
- affected4.0(4j)
- affected4.0(2m)
- affected4.0(2k)
- affected4.0(1c)
- affected4.0(4f)
- affected4.0(4c)
- affected3.1(3d)
- affected3.1(2g)
- affected3.1(2c)
- affected4.0(1d)
- affected3.1(2e)
- affected4.0(1a)
- affected4.0(1b)
- affected3.1(3b)
- affected4.0(4b)
- affected3.1(2b)
- affected4.0(4e)
- affected3.1(3h)
- affected4.0(4l)
- affected4.1(1g)
- affected4.1(2a)
- affected4.0(2n)
- affected4.1(1h)
- affected3.1(3k)
- affected4.1(2b)
- affected4.0(2o)
- affected4.0(4m)
- affected4.1(2d)
- affected4.1(3b)
- affected4.0(2p)
- affected4.1(2e)
- affected4.1(2f)
- affected4.0(4n)
- affected4.0(2q)
- affected4.1(3c)
- affected4.0(2r)
- affected4.1(3d)
- affected4.1(2g)
- affected4.1(2h)
- affected4.1(3g)
- affected4.1(3f)
- affected4.1(2j)
- affected4.1(2k)
- affected4.1(3h)
- affected4.2(2a)
- affected4.1(3i)
- affected4.2(2f)
- affected4.2(2g)
- affected4.2(3b)
- affected4.1(3l)
- affected4.2(3d)
- affected4.3(1.230097)
- affected4.2(1e)
- affected4.2(1b)
- affected4.2(1j)
- affected4.2(1i)
- affected4.2(1f)
- affected4.2(1a)
- affected4.2(1c)
- affected4.2(1g)
- affected4.3(1.230124)
- affected4.1(2l)
- affected4.2(3e)
- affected4.3(1.230138)
- affected4.2(3g)
- affected4.3(2.230207)
- affected4.2(3h)
- affected4.2(3i)
- affected4.3(2.230270)
- affected4.1(3m)
- affected4.1(2m)
- affected4.3(2.240002)
- affected4.3(3.240022)
- affected4.2(3j)
- affected4.1(3n)
- affected4.3(2.240009)
- affected4.3(3.240041)
- affected4.2(3k)
- affected4.3(3.240043)
- affected4.3(4.240142)
- affected4.3(2.240037)
- affected4.3(2.240053)
- affected4.3(4.240152)
- affected4.2(3l)
- affected4.3(2.240077)
- affected4.3(4.242028)
- affected4.3(4.241063)
- affected4.3(4.242038)
- affected4.2(3m)
- affected4.3(2.240090)
- affected4.3(5.240021)
- affected4.3(2.240107)
- affected4.3(4.242066)
- affected4.2(3n)
- affected4.3(5.250001)
- affected4.2(3o)
- affected4.3(2.250016)
- affected4.3(2.250021)
- affected4.3(5.250030)
- affected4.3(2.250022)
- affected4.3(6.250039)
- affected4.3(6.250040)
- affected4.3(5.250033)
- affected4.3(6.250044)
- affected4.3(6.250053)
- affected4.3(2.250037)
- affected4.3(2.250045)
- affected4.3(4.252001)
- affected4.3(4.252002)
- affected6.0(1.250127)
- affected4.2(3p)
- affected6.0(1.250131)
- affected4.3(6.250101)
- affected6.0(1.250174)
- affected4.3(6.250117)
- affected4.3(5.250043)
- affected4.3(5.250045)
- affected4.3(6.250060)
- affected6.0(1.250130)
- affected4.3(4.241014)
- affected4.3(2.250063)
- affected6.0(1.250192)
- affected4.3(6.260003)
- affected6.0(1.250194)
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.