HackerFeeds

CyberSecurity News

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

The Hacker News
· July 28, 2026

AI summary

Cybersecurity researchers have discovered a large number of Baseboard Management Controller management interfaces exposed to the public internet, with over 36,000 instances found to be running the Intelligent Platform Management Interface protocol. Of these, more than 24,000 disclose password-derived authentication hashes before login. This vulnerability is due to the exposure of IPMI protocol to the public internet. The exposed interfaces can potentially be accessed by unauthorized parties. The researchers have raised an alert regarding this issue, which affects a significant number of server-management interfaces. The exposed password hashes can be used to gain unauthorized access to the systems.

Read the full article at The Hacker Newsthehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.