Snapshot from Aug 24, 2026 at 07:00 UTC. For live data and tracking: View Live
Tech security research

BMC vulnerabilities exposed in enterprise servers

Analysis based on 7 articles · First reported Aug 05, 2026 · Last updated Aug 18, 2026

Sentiment
-40
Attention
4
Articles
7
Market Impact
General
Live prominence charts, article sentiment distribution, and event development timeline available on the Ergen Dashboard

The disclosure of widespread BMC vulnerabilities could increase demand for security patching and monitoring solutions, benefiting cybersecurity firms. Server manufacturers may face reputational damage and potential liability, while enterprises may incur costs to remediate affected infrastructure.

Technology Cybersecurity Data Center

At the Black Hat security conference, firmware security expert H. D. Moore presented research revealing widespread critical vulnerabilities in baseboard management controllers (BMCs) embedded in enterprise servers from major manufacturers including HPE, Supermicro, Dell, Lenovo, Huawei, and others. BMCs are miniature computers that manage servers remotely, even when powered off. Moore's scans found over 86,000 Internet-exposed BMCs, with more than 54% containing critical vulnerabilities, and an internal scan of 126,761 BMCs found nearly 29% with critical flaws. Many devices remain vulnerable to CVE-2013-4786, a decade-old IPMI authentication flaw. The vulnerabilities span authentication bypasses, encryption failures, predictable session IDs, memory corruption, unsigned firmware, and extractable secrets. Real-world exploits like ILObleed demonstrate the severity. Moore released an open-source scanner, OOBscan, to help administrators detect vulnerable BMCs.

70 Hewlett-Packard affected by vulnerabilities
70 Supermicro affected by vulnerabilities
60 H. D. Moore presented findings
60 Dell Technologies affected by vulnerabilities
50 Lenovo affected by vulnerabilities
50 Huawei affected by vulnerabilities
40 Avocent affected by vulnerabilities
40 H3C Technologies affected by vulnerabilities
40 Nvidia affected by vulnerabilities
40 American Megatrends affected by vulnerability
30 Intel affected by vulnerabilities
per
Lead researcher who presented the findings and released OOBscan, enhancing his reputation in firmware security.
Importance 90.0 Sentiment 0.0
stock
Affected by multiple critical vulnerabilities in iLO, including pre-auth RCE and weak default credentials, posing security risks to customers.
Importance 80.0 Sentiment -30.0
stock
Affected by predictable session IDs, firmware integrity issues, and extractable secrets, increasing risk of compromise.
Importance 80.0 Sentiment -30.0
stock
Affected by firmware integrity and secret extraction vulnerabilities, requiring patching.
Importance 60.0 Sentiment -20.0
priv
Affected by extractable secrets and other BMC flaws, potentially impacting enterprise customers.
Importance 50.0 Sentiment -20.0
priv
Moore's company, which may gain visibility and credibility from the research.
Importance 40.0 Sentiment 20.0
stock
Mentioned as affected by BMC vulnerabilities, though specific details are limited.
Importance 40.0 Sentiment -10.0
priv
Affected by authentication and firmware integrity issues in OpenBMC-derived systems.
Importance 40.0 Sentiment -10.0
oth
Conference where the research was presented, providing a platform for disclosure.
Importance 30.0 Sentiment 0.0
priv
Listed as affected by BMC vulnerabilities, though details are sparse.
Importance 30.0 Sentiment -10.0
stock
Affected via OpenBMC-derived products, though impact is limited.
Importance 30.0 Sentiment -10.0
stock
Legacy systems affected by session encryption failures, but not a primary focus.
Importance 30.0 Sentiment -10.0
govactor
Previously documented exploited BMC vulnerabilities, highlighting the threat.
Importance 30.0 Sentiment 0.0
priv
Mentioned as having a critical vulnerability added to CISA's exploited list, but not central to this research.
Importance 20.0 Sentiment -10.0
ERGEN INTELLIGENCE
Track this event live

Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.

Open Dashboard

About Ergen

Ergen is a news intelligence platform that converts raw news articles into structured data. It tracks events, entities, and the relationships between them, with sentiment and attention metrics derived from thousands of articles. Pages on this site are daily static snapshots from the platform's live database. For real-time tracking, search, and alerts, the full dashboard is at app.ergen.ai.