VORANT. Threat Intelligence Sign in Get the full feed

Cisco UCS UEFI Secure Boot bypass flaw

routine vulnerability technologyinfrastructure

A Cisco advisory details a security policy bypass vulnerability affecting UCS Server Software, Intersight Server Firmware, NFVIS and UCS BIOS/E-Series products via UEFI Secure Boot.

ANSSI (CERT-FR) republished a Cisco security advisory describing CVE-2026-20293, a vulnerability affecting a broad range of Cisco Unified Computing System (UCS) products, Intersight Server Firmware, NFVIS, and UCS E-Series BIOS/software. The flaw allows an attacker to bypass a security policy, specifically related to UEFI Secure Boot (cisco-sa-ucs-uefi-sb-bypass), potentially undermining boot-time integrity protections on affected hardware.

The advisory lists numerous affected version ranges across UCS Server Software (versions 1.2 through 6.0), UCS XE-Series Server Firmware, Intersight Server Firmware, NFVIS, and UCSE BIOS/Software, with fixes scheduled or released between September and October 2026. No evidence of active exploitation is mentioned in the bulletin. Defenders operating Cisco UCS infrastructure should consult the Cisco advisory to identify their specific product/version and apply the corresponding patch or firmware update once available, prioritizing systems where Secure Boot integrity is a security control relied upon for supply-chain or firmware-tampering protection.

Mentioned in this report

Vulnerabilities CVE-2026-20293

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1138

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free