Security Advisory Desk
highQCS priority 100/100Cisco

Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

Cisco UCS servers and related appliances have a security weakness in their UEFI Shell firmware component. Attackers with user credentials or physical access can bypass Secure Boot protections, enabling them to run unauthorized software when the system starts up. This happens because the UEFI Shell allows memory changes even when Secure Boot is on, letting attackers modify security settings. Cisco has released updated software to fix this issue, but no temporary fixes are available, so upgrades are important to stay safe.

Published 8/9/2026, 4:00:00 pmVerified 8/9/2026, 10:39:49 pmRevision 1
Cisco high network security advisory visual

In plain language

What this advisory means

Cisco UCS servers and related appliances have a security weakness in their UEFI Shell firmware component. Attackers with user credentials or physical access can bypass Secure Boot protections, enabling them to run unauthorized software when the system starts up. This happens because the UEFI Shell allows memory changes even when Secure Boot is on, letting attackers modify security settings. Cisco has released updated software to fix this issue, but no temporary fixes are available, so upgrades are important to stay safe.

Technical explanation

How the issue affects the environment

The vulnerability resides in the UEFI Shell implementation on Cisco UCS Servers and UCS-based appliances with UEFI Secure Boot enabled. The UEFI Shell's memory write commands are accessible during boot, allowing an authenticated user or anyone with physical access to invoke the UEFI Shell boot option, use these commands to alter UEFI memory variables, specifically those governing Secure Boot validation. This manipulation can bypass Secure Boot's integrity checks, permitting unauthorized, potentially malicious code execution in the preboot environment. Cisco addressed this by removing memory modification commands from the UEFI Shell when Secure Boot is enabled.

Operational impact

Why teams should care

Successful exploitation permits attackers to override UEFI Secure Boot protections on critical Cisco UCS servers and appliances, which jeopardizes device trustworthiness, enables unauthorized software execution at startup, and risks compromise of sensitive workloads and data. This can impact operational integrity, confidentiality, and compliance, leading to potential business disruption and reputational harm.

Immediate action

Apply Cisco's provided software updates for the Cisco UCS Servers and UCS-based appliances. Upgrade the BIOS and firmware to the fixed versions that remove memory write commands from the UEFI Shell when UEFI Secure Boot is enabled. Follow Cisco's official upgrade instructions carefully to fully remediate the vulnerability.

Affected and fixed releases

Affected versionsVersions prior to the listed fixed releases on affected Cisco UCS and UCS-based appliances running vulnerable BIOS with UEFI Secure Boot enabled
Fixed versionsFixed software releases specified per product group, for example Cisco UCS Server Software Release 4.3(6h), 6.0(2d) and later; Cisco Integrated Management Controller and BIOS fixed, 5000 Series ENCS with Cisco NFVIS 4.15.7 and later; various appliances with latest firmware updates mentioned in advisory; see full advisory for exact fixed builds.

Temporary risk reduction

There are no workarounds available that mitigate this vulnerability. Upgrading to fixed software releases is the only effective remediation.

Evidence and validation checklist

  • Cisco official security advisory published on 2026-09-08
  • CVE-2026-20293 assigned to the vulnerability
  • Detailed affected product lists and fixed versions in advisory
  • Description of technical cause: memory write commands in UEFI Shell facilitate Secure Boot bypass
  • Confirmation of released software updates addressing the issue
  • Confirmation that no workarounds exist

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source