High [CVE-2026-20293] Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
This high-severity Cisco advisory covers CVE-2026-20293 affecting Unified Computing System E-Series Software (UCSE), Unified Computing System (Managed), Unified Computing System (Standalone).
Android app · Google Play
Monitor future Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software.
The flaw is caused by the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device.
Affected products named by the advisory: Unified Computing System E-Series Software (UCSE); Unified Computing System (Managed); Unified Computing System (Standalone); Enterprise NFV Infrastructure Software.
- Scope: This vulnerability affects the following Cisco products if they have UEFI Secure Boot enabled and are running a vulnerable BIOS version:
- Release 4.15 and earlier (first fixed: 4.15.7 (Oct 2026))
- Earlier than 4.3 — Migrate to a fixed release
- Release 4.3 (first fixed: 4.3(6h)1)
- Release 6.0 (first fixed: 6.0(2d)1)
- Earlier than 5.4 — Migrate to a fixed release
- Release 5.4 (first fixed: 5.4(0.260050)1)
- Release 6.0 (first fixed: 6.0(2.260143))
- Release 5.4 (first fixed: 5.4(0.260042))
- Release 2.0 (first fixed: Release no. TBD (Oct 2026))
- Release 4.0 (first fixed: 4.0(2.260004))
- Release 1.2 and earlier (first fixed: Release no. TBD (Sep 2026))
- Earlier than 4.2 — Migrate to a fixed release
- Release 4.2 (first fixed: 4.2(3r))
- Release 4.3 (first fixed: 4.3(2.260020))
- Release 4.3 (first fixed: 4.3(6.260054))
- Release 6.0 (first fixed: 6.0(2.260143)1)
- Release 4.2 (first fixed: 4.2(3s))
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
- 4.15.7 (Oct 2026)
- 4.3(6h)1
- 6.0(2d)1
- 5.4(0.260050)1
- 6.0(2.260143)
- 5.4(0.260042)
- Release no. TBD (Oct 2026)
- 4.0(2.260004)
- Release no. TBD (Sep 2026)
- 4.2(3r)
- 4.3(2.260020)
- 4.3(6.260054)
- 6.0(2.260143)1
- 4.2(3s)
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Mitigation checklist
- Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
- Release 4.15 and earlier: upgrade to 4.15.7 (Oct 2026).
- Earlier than 4.3: migrate to a fixed release.
- Release 4.3: upgrade to 4.3(6h)1.
- Release 6.0: upgrade to 6.0(2d)1.
- Earlier than 5.4: migrate to a fixed release.
- Release 5.4: upgrade to 5.4(0.260050)1.
- Release 6.0: upgrade to 6.0(2.260143).
- Earlier than 5.4: migrate to a fixed release.
- There are no workarounds that address this vulnerability.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.