THREATOPS
THREAT OPSThreat News › Have you patched? Are you sure? The story of the sticky Supermicro BMC bugs

Have you patched? Are you sure? The story of the sticky Supermicro BMC bugs

lowbinarlyPublished 2026-01-26

After repeatedly bypassing Supermicro's BMC firmware validation fixes, we detail CVE-2025-12006 and CVE-2025-12007 — the latest in a year-long chain of vulnerabilities that allowed persistent arbitrary code execution through manipulated firmware update images. We walk through each bypass technique, analyze the final patches, and assess whether these critical issues are truly resolved.

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.binarly.io/blog/have-you-patched--are-you-sure--the-story-of-the-sticky-supermicro-bmc-bugs