Lots of Internet-exposed server management controllers are subject to offline password-cracking attacks — and adversaries have taken note.
July 28, 2026
Some 24,000 Internet-exposed server management controllers are vulnerable to a more than 20-year-old flaw that gives attackers a way to crack authentication credentials and gain privileged access to the underlying servers.
The issue can evade conventional security tools because these management controllers operate independently of the server's operating system, kernel, containers, and workloads, and are therefore nearly invisible at those layers.
Researchers at Lava discovered the flaw when researching Internet-exposed Baseboard Management Controllers (BMCs) for vulnerabilities and said it found evidence of attackers having exploited the issue in the wild.











