📣 Send us your press release
Site updates every 15 minutes
Technology

Motherboard Controllers Pose Remote Backdoor Risk to Thousands of Servers

New research reveals that thousands of enterprise servers are vulnerable to remote takeovers due to critical, long-standing flaws within their motherboard management controllers.

5 August 2026
Motherboard Controllers Pose Remote Backdoor Risk to Thousands of Servers

Thousands of internet-connected servers manufactured by major companies can be remotely compromised by exploiting critical vulnerabilities found deep within the system's motherboard controllers, according to research presented Wednesday. Some of these flaws are reportedly over a decade old.

The vulnerabilities lie within Baseboard Management Controllers (BMCs), which are essentially miniature computers embedded in virtually every enterprise server motherboard. BMCs operate with their own operating system firmware and network stack, providing administrators with essential "lights out" and "out-of-band" management capabilities. These allow for monitoring and control of servers, including reboots and OS installations, even when the main server is powered off or unresponsive.

Researchers have warned about the security risks posed by BMCs since at least 2013. The Intelligent Platform Management Interface (IPMI) protocol, which enables BMCs to operate independently and perform administrative tasks, has been a particular point of concern. Exploiting vulnerabilities within IPMI firmware can allow attackers to execute malicious code directly on the BMC, potentially leading to full control over the managed server.

The research highlights BMCs as a "pervasive, under-monitored, under-patched parallel attack surface." The fact that BMC firmware is often updated less frequently than a server's main operating system makes these controllers an attractive, yet vulnerable, target for sophisticated attackers.

Original source: arstechnica.com