CISCO Security Advisory
Published Date: Not specified
CVE: CVE-2026-20293
Advisory Summary
๐ ๐ Cisco UCS & UCS-Based Appliances: UEFI Shell Secure Boot Bypass (High Severity)
โ ๏ธ What happened
Cisco has disclosed a High impact vulnerability in the UEFI Shell implementation on Cisco UCS Servers and UCS-based appliances. It could allow an attacker to bypass UEFI Secure Boot validation and execute unauthorized software by manipulating UEFI pre-boot memory variables.
- Authenticated attacker: Valid credentials for a user account with role user or admin
- Unauthenticated attacker: Physical access to the device (to access/select boot options)
๐ Root cause
When UEFI Secure Boot is enabled, the UEFI Shell still exposes memory write commands, enabling modification of UEFI memory variables that influence Secure Boot behavior.
๐ ๏ธ Cisco fix status
โ
Updates released by Cisco address the vulnerability.
๐ซ No workarounds are available for this issueโpatching (and validation) is the primary mitigation path.
- Pre-OS compromise / persistence: Attack occurs before the OS fully boots, increasing stealth and persistence potential.
- Credential-to-firmware escalation: Stolen/abused credentials for UCS user roles can become a firmware-level execution vector.
- Physical access risk amplification: If devices are not locked down (console/boot access), Secure Boot can be undermined.
- Restrict who can enable/choose UEFI Shell at boot time.
- Enforce least privilege for UCS roles (reduce admin/user credential misuse risk).
- CVE-2026-20293
๐
-2026-20293