Thousands of servers can be backdoored by exploiting buggy motherboard controllers
A widespread vulnerability in baseboard management controllers from major manufacturers allows attackers to backdoor thousands of servers via firmware flaws.

- A critical flaw in baseboard management controllers (BMCs) from major vendors (Dell, HPE, Supermicro) enables remote backdoor attacks on thousands of servers.
- The vulnerability (CVE-2026-XXXX) has a CVSS score of 9.8, allowing persistent, undetectable compromise even when systems are offline.
- Firmware-level attacks are hard to detect and can survive OS reinstalls or hardware swaps, posing long-term risks.
- Security teams must prioritize patching, though widespread deployment may delay mitigation efforts.
Security researchers have disclosed a critical vulnerability in baseboard management controllers (BMCs) from leading manufacturers, which could allow attackers to remotely backdoor thousands of servers. The flaw stems from insecure firmware implementations in widely used server motherboard chips, enabling unauthorized access even when systems are powered off or disconnected from networks.
The issue affects BMCs from major vendors, including Dell, HPE, and Supermicro, which are standard components in data center servers. Attackers exploiting the flaw could gain persistent control over compromised systems, install malware, or exfiltrate sensitive data. The vulnerability has been assigned CVE-2026-XXXX and carries a CVSS score of 9.8, indicating its critical severity.
Firmware-level vulnerabilities are particularly dangerous because they are difficult to detect and can survive operating system reinstalls or hardware replacements. Security teams are urged to apply patches immediately, though many organizations may face challenges due to the distributed nature of affected systems.
Developers must audit BMC firmware and prioritize security updates to prevent firmware-level compromises.
Companies with data centers or cloud infrastructure face severe risks of data breaches and operational disruption.
Investors in hardware or data center security firms may see increased demand for mitigation solutions.
This highlights the growing threat of firmware vulnerabilities and the need for better security practices in hardware supply chains.
- Baseboard Management Controller (BMC)
- A specialized microcontroller embedded on server motherboards that enables remote management and monitoring, even when the system is powered off.
- CVSS score
- Common Vulnerability Scoring System, a standardized metric (0-10) used to assess the severity of security vulnerabilities.
SecurityOpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
SecurityAnthropic’s AI used fake identities, malware in rogue attack on GitHub project
The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
SecurityAI Hacks Are Bad. AI Worms and Viruses Will Be Worse
SecurityMeta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
Stanford Medicine researchers awarded $20 million for AI-guided research facilities - Stanford Medicine
Stanford Medicine researchers have been awarded $20 million to establish AI-guided research facilities. The funding will support the development of cutting-edge research infrastructure.
Susquehanna awarded nearly $100,000 to advance AI education - Susquehanna University
Susquehanna University received nearly $100,000 to advance AI education. The grant aims to improve AI-related curriculum and resources.
AI ToolsResize One Image into 6 Social Media Formats Automatically Using Cloudinary Claimable Clouds
Cloudinary launches a new AI-powered feature that automatically resizes a single image into six optimized formats for major social media platforms.
AI ToolsMeta launches Muse Code, an AI agent for large code bases
Meta has introduced Muse Code, a new AI agent designed to assist developers in handling large and complex codebases.
URAC Awards First Health Care Artificial Intelligence Accreditations to Guidehealth, RediMinds, and SandsRx - HIT Consultant
URAC has awarded its first artificial intelligence accreditations to Guidehealth, RediMinds, and SandsRx. This recognition is for their AI solutions in healthcare.
NSF launches $100M AI hub program - Community College Daily
The National Science Foundation (NSF) has launched a $100 million AI hub program for community colleges, aiming to boost AI education and research.