---
url: "https://www.xcademia.com/news/cisco-ucs-uefi-secure-boot-bypass-vulnerability-rated-high-poc-code-available"
title: "Cisco UCS UEFI Secure Boot Bypass Vulnerability Rated High, PoC Code Available"
description: "Cisco warns of a high-severity UCS UEFI Secure Boot bypass flaw, CVE-2026-20293. PoC code is available and Cisco urges affected customers to upgrade."
publishedAt: "2026-09-10T08:54:34.633+00:00"
updatedAt: "2026-09-10T08:54:45.625489+00:00"
type: news
category: cybersecurity
source_name: "Cisco Security Advisory "
source_url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW"
tags:
  - "#Cisco"
  - "#Cybersecurity"
  - "#CVE202620293"
  - "#UEFI"
  - "#SecureBoot"
  - "#FirmwareSecurity"
  - "#Vulnerability"
  - "#UCS"
---

# Cisco UCS UEFI Secure Boot Bypass Vulnerability Rated High, PoC Code Available

> Cisco has disclosed a high-severity vulnerability in the UEFI Shell of UCS servers and UCS-based appliances that can bypass Secure Boot checks. Cisco says proof-of-concept exploit code is available and urges customers to upgrade to fixed releases.

Source: **Cisco Security Advisory ** · 10 September 2026

## Cisco discloses high-severity UEFI Secure Boot bypass flaw in UCS systems

Cisco has disclosed a high-severity vulnerability affecting the UEFI Shell implementation in Cisco UCS servers and UCS-based appliances.

Tracked as **CVE-2026-20293**, the vulnerability carries a **CVSS base score of 7.1**. Cisco says the flaw could allow an authenticated attacker with valid credentials for a user or admin account, or an unauthenticated attacker with physical access to an affected device, to bypass UEFI Secure Boot validation checks and execute unauthorized software.

The vulnerability is tied to memory write commands available within the UEFI Shell while UEFI Secure Boot is enabled.

Cisco published the advisory on September 8, 2026, and says software updates are available for affected platforms. There are no workarounds that address the vulnerability.

## How the UEFI Secure Boot bypass works

UEFI Secure Boot is designed to validate software involved in the boot process before allowing it to execute.

According to Cisco, the affected UEFI Shell implementation includes multiple commands capable of modifying memory. When Secure Boot is enabled, those commands could be used to manipulate the preboot environment.

An attacker could select the UEFI Shell boot option during startup and use available shell commands to modify UEFI memory variables.

Cisco says this could allow an attacker to overwrite memory values associated with UEFI Secure Boot and effectively bypass Secure Boot validation.

The result could be the execution of unauthorized software on the affected device.

### 

![info-1](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1789022048877-info-1--137-.webp)

## 
Which Cisco products are affected?

Cisco says the vulnerability affects listed products when **UEFI Secure Boot is enabled and the system is running a vulnerable BIOS version**.

Affected Cisco platforms include:

- 5000 Series Enterprise Network Compute Systems
- UCS B-Series Blade Servers
- UCS C-Series Rack Servers
- UCS C845A M8 Rack Server
- UCS C885A M8 Rack Server
- UCS C880A M8 Rack Server
- UCS E-Series M3 Servers
- UCS E-Series M6 Servers
- UCS S-Series Storage Servers
- UCS X-Series Modular System
- Unified Edge

The advisory also identifies Cisco appliances based on preconfigured UCS C-Series servers.

These include:

- Application Policy Infrastructure Controller Servers
- Cisco Telemetry Broker Appliances
- HyperFlex Edge Nodes
- HyperFlex Nodes
- IEC6400 Edge Compute Appliances
- IOS XRv 9000 M7 Appliances
- Nexus Dashboard Appliances
- Secure Email Gateways
- Secure Email and Web Manager
- Secure Endpoint Private Cloud Appliances
- Secure Firewall Management Center Appliances
- Secure Malware Analytics Appliances
- Secure Network Analytics Appliances
- Secure Network Server appliances
- Secure Web Appliances

Cisco notes that these appliances are affected when they support UEFI Secure Boot and expose access to a keyboard, video and mouse console or virtual KVM console.

For Secure Email Gateways, Secure Email and Web Manager, Secure Web Appliances and certain other listed platforms, Cisco says physical KVM access is required for exploitation, which significantly reduces the attack vector on those platforms.

Cisco also states that only products listed in the advisory's Vulnerable Products section are known to be affected.

## 
The vulnerability is specifically tied to the UEFI Shell

The UEFI Shell provides a command-line environment for debugging, scripting and controlling boot-related options.

On Cisco UCS servers operating in UEFI boot mode, the shell can be available as a boot option.

The security problem arises because the shell contains commands that can modify memory.

With Secure Boot enabled, Cisco says those capabilities can be used to manipulate the preboot environment and potentially overwrite memory values used during Secure Boot validation.

This means the security boundary provided by Secure Boot can be undermined before the operating system has fully loaded.

### 

![info-2](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1789022081882-info-2--118-.webp)

## 
Cisco's fix removes memory modification commands

Cisco says it addressed the vulnerability by removing UEFI Shell commands that allow memory modifications when UEFI Secure Boot is enabled.

The company has released fixed software for multiple affected product families.

However, the remediation path varies depending on the Cisco platform, software version and management mode.

For example, Cisco lists fixed releases for UCS B-Series and X-Series systems under UCS Manager and Intersight Managed Mode, as well as different firmware releases for UCS C-Series systems.

Some affected platforms also have fixes scheduled for September or October 2026.

Cisco therefore recommends that customers consult the advisory's fixed software tables and upgrade to the appropriate fixed release.

## 
Fixed software varies by platform

The advisory contains separate remediation information for different UCS product families.

Some notable fixed releases include:

Affected platform

Fixed release information

5000 Series ENCS

NFVIS 4.15.7, listed for October 2026

UCS B-Series and X-Series in UCS Manager Mode

4.3(6h), 6.0(2d), depending on release

UCS B-Series in Intersight Managed Mode

5.4(0.260050), 6.0(2.260143), depending on release

UCS X-Series in Intersight Managed Mode

5.4(0.260042), 6.0(2.260143), depending on release

UCS C880A M8

4.0(2.260004)

UCS C885A M8

Fixed release listed as TBD for September 2026

UCS C845A M8

Fixed release listed as TBD for October 2026

UCS C-Series M5

4.2(3r) or 4.3(2.260020), depending on release

UCS C-Series M6, M7 and M8

4.2(3r), 4.3(6.260054), or 6.0(2.260143), depending on release

UCS E-Series M3

BIOS 4.04

UCS E-Series M6

4.15.4-b1

UCS S-Series

4.3(6.260054)

Unified Edge

6.0(2.260143)

Cisco also provides separate remediation instructions for several UCS-based appliances.

Administrators should use Cisco's advisory rather than applying a fixed release from another product family based only on the version number.

Additional details were not disclosed in the announcement.

## 
Some appliance fixes require product-specific procedures

For UCS-based appliances, Cisco says administrators can generally perform a direct Cisco IMC and BIOS upgrade using the fixed releases listed in the advisory.

There are exceptions.

For example, Cisco provides separate remediation instructions for products including Cisco Telemetry Broker, IEC6400 Edge Compute Appliances, IOS XRv 9000 M7 Appliances, Secure Firewall Management Center, Secure Malware Analytics and Secure Network Analytics.

Some appliances require firmware packages, hotfixes, Host Upgrade Utility procedures or product-specific upgrade instructions.

This makes asset identification particularly important for organizations operating multiple Cisco security and infrastructure appliances built on UCS hardware.

### 

![info-3](https://0a515t3ure77wbvx.public.blob.vercel-storage.com/articles/1789030064892-info-3--111-.webp)

## 
No workaround is available

Cisco explicitly states that there are **no workarounds** that address this vulnerability.

The company considers workarounds and mitigations, where applicable, to be temporary solutions until a fixed software release is available.

Cisco recommends upgrading to the fixed software identified in the advisory to remediate the vulnerability and avoid future exposure.

Organizations should also verify that their devices have sufficient memory and that existing hardware and software configurations remain supported after an upgrade.

## 
Proof-of-concept exploit code is available

One of the more important disclosures in the advisory is Cisco's statement about exploitation status.

The Cisco Product Security Incident Response Team, or PSIRT, says it is **aware that proof-of-concept exploit code is available** for CVE-2026-20293.

At the same time, Cisco says PSIRT is **not aware of malicious use** of the vulnerability.

This distinction is important.

The availability of proof-of-concept code means security teams should not treat the issue as purely theoretical. However, Cisco has not reported known malicious exploitation at the time of publication.

Cisco credits **Stas Lyakhov from Eclypsium** with reporting the vulnerability.

## 
Why the vulnerability matters to infrastructure teams

The issue highlights the importance of protecting the systems that operate before an operating system starts.

Secure Boot is intended to establish trust during the early stages of system startup. A vulnerability in the preboot environment can therefore affect a security control that organizations may rely on before the operating system and its normal security tooling are running.

In this case, Cisco's advisory identifies the UEFI Shell's memory modification capabilities as the underlying issue.

The affected attack paths also differ by platform.

Some systems can be targeted by an authenticated attacker with a user or admin role, while certain appliance environments require physical KVM access.

For enterprises, this means remediation should be based on the exact Cisco platform and configuration rather than treating every affected product as having the same exposure.

**Source Fact vs. Industry Context**

**Source fact:** Cisco says CVE-2026-20293 can allow an attacker to bypass UEFI Secure Boot validation by using UEFI Shell memory modification capabilities when Secure Boot is enabled.

**Industry context:** The announcement highlights a broader security challenge around firmware and preboot components. Security controls at the operating-system level cannot by themselves address vulnerabilities that occur earlier in the boot process.

## 
What administrators should do now

Organizations using Cisco UCS infrastructure or UCS-based appliances should prioritize the following actions:

1. **Identify affected systems.**
Review Cisco's Vulnerable Products list and determine whether affected UCS servers or UCS-based appliances are deployed.
2. **Check the Secure Boot configuration.**
Cisco states that affected products are vulnerable when UEFI Secure Boot is enabled and a vulnerable BIOS version is running.
3. **Check the current firmware and software release.**
Match the installed version against Cisco's fixed software tables.
4. **Determine the correct remediation path.**
Some platforms use Cisco IMC and BIOS upgrades, while certain appliances require product-specific firmware packages or procedures.
5. **Plan upgrades carefully.**
Cisco advises customers to verify hardware and software compatibility and available system resources before upgrading.
6. **Monitor the advisory for changes.**
Some fixed releases listed by Cisco are scheduled for September or October 2026.
7. **Treat PoC availability as a reason for timely remediation.**
Cisco says proof-of-concept exploit code is available, although PSIRT is not aware of malicious exploitation.

Cisco's advisory remains the authoritative source for affected versions and fixed releases.

## 
The broader takeaway

CVE-2026-20293 is not an operating-system vulnerability. It sits in the UEFI Shell and affects the security boundary established during system startup.

Cisco's remediation removes memory modification commands from the UEFI Shell when UEFI Secure Boot is enabled.

The advisory also demonstrates why firmware security requires the same attention as software security. Infrastructure teams need visibility into BIOS versions, firmware releases, boot configurations and the remediation paths associated with individual hardware platforms.

For organizations running Cisco UCS environments, the immediate priority is straightforward: determine whether affected systems are present, identify their current firmware versions and apply the appropriate Cisco fix.

Cisco has not disclosed any workaround that addresses the vulnerability.

## 
Final assessment

**CVE-2026-20293** is a **High-severity** Cisco UCS vulnerability with a **CVSS score of 7.1** that can undermine UEFI Secure Boot validation through memory modification capabilities in the UEFI Shell.

The situation warrants attention because Cisco has confirmed that proof-of-concept exploit code is available.

At the time of the advisory's publication, however, Cisco said its PSIRT team was not aware of malicious exploitation.

Organizations should therefore focus on accurate asset identification and timely firmware remediation, using Cisco's product-specific fixed-release guidance.

## Original source

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW

## Tags

`#Cisco` · `#Cybersecurity` · `#CVE202620293` · `#UEFI` · `#SecureBoot` · `#FirmwareSecurity` · `#Vulnerability` · `#UCS`

---

## About this content

This Markdown news article is the citation-grade twin of [Cisco UCS UEFI Secure Boot Bypass Vulnerability Rated High, PoC Code Available](https://www.xcademia.com/news/cisco-ucs-uefi-secure-boot-bypass-vulnerability-rated-high-poc-code-available). It is published by **Xcademia** (UK Companies House 12322710) and is available for AI search engines and large language models to index, summarise, and cite.

When citing or quoting, please attribute *Xcademia* and link back to the source URL above.

- Source: https://www.xcademia.com/news/cisco-ucs-uefi-secure-boot-bypass-vulnerability-rated-high-poc-code-available
- Publisher: Xcademia — https://www.xcademia.com
- Catalogue index: https://www.xcademia.com/llms-full.txt
