CVE-2026-6485

Unified Computing System (UCS): Active Debug Code (CVE-2026-6485)

mediumEPSS 0.2%

Affected

  • Cisco/Unified Computing System (UCS) = UEFI Shell implementation..UEFI Shell implementation
  • Insyde/UEFI Firmware < *..05.2B.17
  • Insyde/UEFI Firmware < *..05.3A.17
  • Insyde/UEFI Firmware < *..05.48.17
  • Insyde/UEFI Firmware < *..05.56.17
  • Insyde/UEFI Firmware < *..05.63.17
  • Insyde/UEFI Firmware < *..05.72.17

Fixed in

  • Insyde/UEFI Firmware 05.2B.17
  • Insyde/UEFI Firmware 05.3A.17
  • Insyde/UEFI Firmware 05.48.17
  • Insyde/UEFI Firmware 05.56.17
  • Insyde/UEFI Firmware 05.63.17
  • Insyde/UEFI Firmware 05.72.17

Description

UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.

Source: BSI

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

CiscoUnified Computing System (UCS)
UEFI Shell implementation
InsydeUEFI Firmware
< 05.2B.17fixed in 05.2B.17< 05.3A.17fixed in 05.3A.17< 05.48.17fixed in 05.48.17< 05.56.17fixed in 05.56.17< 05.63.17fixed in 05.63.17< 05.72.17fixed in 05.72.17

Metrics

8.2
Source: cna-v3
6.9 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-09-10 12:46 UTC
CWE-489

Weakness classes (CWE)

  • CWE-489Base

    Active Debug Code

    The product is released with debugging code still enabled or active.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-10 15:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-6485","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalIm…
  2. New CVE Received2026-09-09 04:19 UTC· 8338d8cb-57f7-4252-abc0-96fd13e98d21
    • Description: UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
    • CVSS V3.1: AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
    • CWE: CWE-489
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/6xxx/CVE-2026-6485.json">CVE-2026-6485</a>

Linked CVEs