What is a BMC vulnerability, and why it puts thousands of servers at risk

Nearly every enterprise server's motherboard hosts a small auxiliary computer that operates independently of the main processor and operating system: the baseboard management controller, or BMC. This chip lets technicians remotely restart, monitor and service hardware even when the server is completely powered off.
Security researchers have found serious vulnerabilities in the firmware of several widely used BMC manufacturers' products. The flaws allow attackers to bypass authentication and gain full control of the BMC, then use that foothold to reach the rest of the server.
The core reason BMCs are dangerous is their position in the privilege hierarchy — above even the operating system. When an attacker compromises a BMC, malware can persist on the server even after the operating system is reinstalled, because the BMC operates in memory and storage entirely separate from the OS.
Researchers stress that this kind of attack is extremely difficult to detect. Standard antivirus software and security monitoring tools cannot reach the BMC layer, meaning malware can go unnoticed for months or even years.
In an attack scenario, once an attacker gains network access to the BMC, they can alter the server's hardware-level behavior, steal data or render the machine entirely unusable. Cloud providers and large data centers are especially vulnerable to this kind of flaw, since it can affect thousands of servers simultaneously.
Security experts say the root of the problem is that BMC firmware is often left running unpatched for years. Many organizations configure BMC software once during server setup and never update it again.
Affected manufacturers have released patches closing the flaw, but researchers note that the patching process is often slow, since BMC updates can require briefly powering down the server — creating operational friction for systems that need to run continuously.
Experts recommend that organizations completely isolate BMC interfaces from the public internet, allowing access only through trusted management networks. They also advise changing default passwords and regularly auditing BMC logs.
This kind of hardware-level vulnerability is drawing increasing attacker interest compared with software flaws, researchers note, because detection risk is lower and the impact can be far more persistent. Researchers expect this trend to grow in attacks targeting large-scale data centers in coming years.
The security community says the findings serve as another reminder that hardware supply-chain security must be taken as seriously as software security — since even the strongest software defenses can fall short when the hardware layer beneath them is not secure.
Read next

Why large language models won't break symmetric encryption
As AI models solve increasingly complex tasks, some worry they could eventually break modern encryption. Cryptographers explain why symmetric encryption's security rests on a mathematical foundation that pattern-recognition systems like large language models cannot meaningfully shortcut.

What is Muse Code, Meta's new AI agent for large codebases
Meta has introduced Muse Code, a new AI agent built specifically to operate across large, complex software codebases rather than isolated files. The tool aims to understand context across an entire repository, a challenge that has limited earlier generations of AI coding assistants.

What is Starlink Mobile, and how does satellite-to-phone connectivity work
SpaceX says its Starlink Mobile satellite-to-phone service will outperform traditional carriers like AT&T, T-Mobile and Verizon. Here is how direct-to-cell satellite technology actually works, and what it could mean for coverage in rural and remote areas.

Jeff Dean and other top AI researchers are leaving Google to launch their own startup
Jeff Dean, Google's longtime chief scientist, is departing the company alongside several senior researchers to launch an independent AI startup. The move is the latest instance of a broader talent migration from large tech companies toward smaller, founder-led AI labs.

Why has Texas paused new data center grid connections amid surging AI demand?
Texas has paused new large-scale data center connections to its ERCOT-run power grid after a surge of AI-driven interconnection requests threatened to outpace the grid's capacity, according to Ars Technica. The move is notable because the state's governor has spent the past two years promoting Texas as an AI infrastructure 'epicenter.' Similar strained connection queues have also emerged in Virginia and the PJM Interconnection region as AI data centers grow more power-hungry.