Ars Technica
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Wednesday, August 5, 2026
Baseboard management controllers from major server manufacturers contain a vulnerability that could allow attackers to gain unauthorized access to thousands of servers, according to security researchers. Baseboard management controllers are firmware systems that manage hardware functions on servers independently of the main operating system. The vulnerability affects controllers produced by multiple major manufacturers and requires exploitation of a software bug in the controller firmware. Researchers have not disclosed the names of affected manufacturers or the specific technical details of the vulnerability, citing responsible disclosure practices.
