# Cisco UCS UEFI Secure Boot bypass flaw

Published: 2026-09-09 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/02b8f32e-785b-5743-b18a-3ecd35f21a49/cisco-ucs-uefi-secure-boot-bypass-flaw

> A Cisco advisory details a security policy bypass vulnerability affecting UCS Server Software, Intersight Server Firmware, NFVIS and UCS BIOS/E-Series products via UEFI Secure Boot.

ANSSI (CERT-FR) republished a Cisco security advisory describing CVE-2026-20293, a vulnerability affecting a broad range of Cisco Unified Computing System (UCS) products, Intersight Server Firmware, NFVIS, and UCS E-Series BIOS/software. The flaw allows an attacker to bypass a security policy, specifically related to UEFI Secure Boot (cisco-sa-ucs-uefi-sb-bypass), potentially undermining boot-time integrity protections on affected hardware.

The advisory lists numerous affected version ranges across UCS Server Software (versions 1.2 through 6.0), UCS XE-Series Server Firmware, Intersight Server Firmware, NFVIS, and UCSE BIOS/Software, with fixes scheduled or released between September and October 2026. No evidence of active exploitation is mentioned in the bulletin. Defenders operating Cisco UCS infrastructure should consult the Cisco advisory to identify their specific product/version and apply the corresponding patch or firmware update once available, prioritizing systems where Secure Boot integrity is a security control relied upon for supply-chain or firmware-tampering protection.

## Mentioned in this report

- Vulnerabilities: CVE-2026-20293

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1138

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/02b8f32e-785b-5743-b18a-3ecd35f21a49/cisco-ucs-uefi-secure-boot-bypass-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
