Skip to main content
Emerging Threats

Network Management Systems Targeted in Widespread Exploitation Efforts

Network equipment and management consoles line a dimly lit operations center corridor.

“Between August 25 and September 17, InfraTrust tracked 158 new security advisories across 17 vendors, covering 1,699 vulnerabilities.”

Scale and severity: hundreds of advisories, dozens of critical flaws

Eclypsium’s September InfraTrust Pulse cataloged a concentrated burst of infrastructure risk: 158 advisories from 17 vendors, covering 1,699 vulnerabilities. Of those advisories, 42 were rated critical, eight held a maximum CVSS score of 10.0, and 71 could be exploited remotely without authentication. Five advisories contained flaws that were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog during the reporting window.

Cisco management consoles: FMC and ISE exploited and chained

InfraTrust flagged administrative platforms as a central battleground, and the most detailed examples come from Cisco. CVE-2026-20079, a maximum-severity authentication bypass in Cisco Secure Firewall Management Center (FMC), allows an unauthenticated actor to send crafted HTTP requests to the FMC web interface and “execute scripts and commands as root” on vulnerable appliances. Cisco confirmed on September 9 that the vulnerability was being actively exploited, and CISA added the flaw to its KEV catalog that same day.

BleepingComputer reported on July 29 that Cisco had already published hot fixes and indicators of compromise — including the `/var/tmp/license.tmp` indicator — for CVE-2026-20079 and another FMC vulnerability, CVE-2026-20316. The two FMC flaws were later confirmed to have been chained together in attacks. Cisco Talos linked the activity to three threat clusters it tracks as UAT-12197, UAT-11823, and UAT-11988; the observed activity included use of built-in FMC tools for reconnaissance, deployment of tunneling utilities, credential harvesting, and in some cases deployment of Qilin ransomware encryptors.

Sophos Counter Threat Unit analyzed a Linux implant named “timezone_check” recovered from compromised FMC appliances and identified it as a variant of Cyclops Blink. Cisco disclosed six additional FMC vulnerabilities on September 16, including flaws affecting the sftunnel connection FMC uses to communicate with managed firewalls.

Cisco Identity Services Engine (ISE) was also affected. Cisco disclosed ISE advisories on September 16 that included three vulnerabilities with maximum CVSS scores of 10.0. One, CVE-2026-76460, is an authentication bypass in an API that allows an unauthenticated remote attacker to execute commands as root; CISA added the flaw to KEV the same day. Cisco said there are no workarounds, noting that restricting access to the appliance via infrastructure access control lists can prevent remote exploitation.

SonicWall, Check Point, Arista, and Nexus: more management-plane risk

The InfraTrust report shows the pattern extends beyond Cisco. SonicWall SMA 1000 appliances were hit by two actively exploited, chained vulnerabilities: CVE-2026-83548 (a CVSS 10.0 unauthenticated server-side request forgery in the Appliance Work Place interface) and CVE-2026-83549 (an OS command injection in the Appliance Management Console). InfraTrust says the flaws can be chained to achieve unauthenticated remote code execution; CISA added both to KEV on September 2. SonicWall confirmed exploitation and recommended upgrading to the latest hotfix, investigating for signs of compromise, and re-imaging physical appliances or redeploying virtual ones rather than attempting in-place cleaning.

Check Point disclosed three critical, remotely exploitable vulnerabilities requiring no authentication: CVE-2026-85102 (authentication bypass that can lead to remote code execution in Remote Access and Site-to-Site VPN), CVE-2026-85103 (a memory corruption issue also leading to remote code execution), and CVE-2026-91843 (a flaw in the unauthenticated login process that can allow attackers to execute code as root on several management and logging servers). The Dutch Nationaal Cyber Security Centrum urged administrators to install updates, warning that exploitation was imminent.

Arista published 34 advisories on September 9, including two maximum-severity vulnerabilities enabling unauthenticated remote code execution on EOS: CVE-2026-73453 (affecting the P4Runtime service on TCP port 9559) and CVE-2026-73456 (affecting gNPSI). Both features are disabled by default and Arista says there is no known exploitation. InfraTrust also highlighted CVE-2026-20212, a critical Cisco Nexus 9000 vulnerability that can allow unauthenticated root code execution through two debug ports reachable by default on affected switches.

Supply-chain and firmware: CopyFail and the UEFI Shell bypass

InfraTrust detailed how a single upstream defect can ripple across vendors. CVE-2026-31431, a Linux kernel privilege escalation dubbed “CopyFail” and added to CISA’s KEV catalog in May, now appears in 19 separate advisories from six vendors. Arista, F5, Juniper, Extreme Networks, and HPE Aruba each published advisories for products containing the vulnerable component; Dell published 14 advisories covering VxRail, PowerFlex, ThinOS, PowerProtect, and Networking OS10.

Firmware and boot components remain another weak point. Eclypsium disclosed a UEFI Shell Secure Boot bypass via CERT/CC that allows an attacker with access to UEFI boot settings to launch an embedded UEFI Shell normally blocked during startup, modify Secure Boot settings in memory, and run unsigned code before the OS starts. The disclosure produced three tracked CVEs: CVE-2026-20293 for Cisco, CVE-2026-33197 for AMI Aptio-based systems, and CVE-2026-6485 for Insyde. AMI, Dell, Cisco, Lenovo, and Supermicro have released or announced fixes for affected products.

What this means for technologists, procurement leaders, and policymakers

  • Technologists and security teams: InfraTrust’s prescription is explicit — “treat these platforms as high-value targets and patch, monitor, and harden them accordingly.” For SonicWall customers the vendor’s guidance is to upgrade to the latest hotfix, investigate for compromise, and re-image appliances where required.
  • Procurement and operations leaders: the CopyFail example shows a single upstream defect can create 19 separate remediation tasks on different vendor schedules; expect coordination challenges across product lines such as VxRail, PowerFlex, ThinOS, PowerProtect, and Networking OS10.
  • Policymakers and national centers: multiple flaws were added to CISA’s KEV catalog during the reporting window, and the Dutch NCSC publicly urged immediate patching for Check Point — reinforcing that national-level advisories are part of the operational response to fast-moving exploitation.

InfraTrust’s September Pulse frames a clear tactical shift: attackers are focusing on the consoles that hold credentials and push changes across fleets. The report closes on a blunt operational directive — patch, monitor, and harden administrative platforms — leaving defenders with the practical question the record poses: will patch cycles, access controls, and cross-vendor coordination keep pace with adversaries exploiting management planes?

Read the original InfraTrust Pulse summary at BleepingComputer