Security News

Old Server Hardware Flaw Leaves Thousands of Data Centers Exposed

Security Week · 4 Aug 2026
Key Takeaway If your business uses hosted or co-located servers, ask your provider whether their management hardware is exposed to this vulnerability and has been patched.

Security researchers have identified a decades-old vulnerability affecting Baseboard Management Controllers (BMCs), the specialised hardware used to remotely manage servers in data centers. More than 24,000 internet-accessible management interfaces were found to disclose authentication hashes before a user even logs in, giving attackers a potential foothold to crack passwords and gain unauthorised access.

BMCs operate at a low level, often outside the reach of standard security software, making them an attractive target for attackers seeking persistent, hard-to-detect access to critical infrastructure. Because this flaw has reportedly existed for years, many organisations may be unaware their server management systems are exposed to the internet at all.

While this issue primarily affects larger data centers and hosting providers, Australian small businesses that rely on cloud services, managed hosting, or co-located servers should ask their providers whether their infrastructure is affected and what steps are being taken to remediate it.

data centers BMC vulnerability server security infrastructure risk third-party risk
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.