A baseboard management controller sits on every enterprise server motherboard.
Every enterprise server motherboard carries a tiny, always-on second computer, a baseboard management controller (or BMC), that runs its own firmware, listens on its own network address, and stays reachable even when the host server is powered off. Admins use this out-of-band, or "lights-out," path to reboot, reinstall, or patch entire fleets from afar. Attackers can use it the same way.
At Black Hat USA 2026 in Las Vegas this week, HD Moore, the runZero CEO who first flagged this management plane as a parallel attack surface in 2013, disclosed more than a dozen new vulnerabilities across BMCs shipped by HPE, Supermicro, Dell, Lenovo, Huawei, Avocent, and others. Several of the weaknesses Moore warned about in 2013, anchored in the IPMI protocol that governs BMC administration, remain exploitable in current firmware. A new CVE, CVE-2024-54085, now sits alongside the older CVE-2013-4786 on the same attack surface.
Compromising a BMC lets an attacker run code on the controller and pivot into every server it manages, installing a backdoor that survives an operating system reinstall on the host. The fleet, not the single machine, is the unit of exposure.
The runZero write-up leaves one operational question for any team running their own datacenter hardware: is the BMC management plane on your network segmented from the data plane, and do you have a current firmware inventory?