Secure Boot flaw affects Cisco UCS systems
The bypass requires account credentials or physical access. Cisco lists fixes by model.
Cisco and CERT describe a Secure Boot bypass affecting certain UCS servers and UCS-based appliances, tracked as CVE-2026-20293. Cisco says exploitation requires valid account credentials or physical access. An attacker could then run unauthorized software before the operating system starts. CERT advises administrators to follow platform-vendor firmware guidance. Cisco lists fixes by product and software branch, with some releases still scheduled. The advisory is not a claim that every Cisco product is affected.
Sources