Critical Network Management Vulnerabilities Are Being Actively Exploited
Attackers are increasingly targeting the management systems used to control corporate infrastructure. Several critical vulnerabilities in these platforms were actively exploited either before or shortly after vendors disclosed them.
The findings come from Eclypsium’s InfraTrust Pulse, a monthly report tracking security advisories affecting network devices, servers, firmware, chips, and other infrastructure.
Between August 25 and September 17, InfraTrust tracked 158 new security advisories from 17 vendors covering 1,699 vulnerabilities.
- 42 advisories were rated critical.
- Eight vulnerabilities received a maximum CVSS score of 10.0.
- 71 vulnerabilities could be exploited remotely without authentication.
- Five advisories included vulnerabilities added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
However, InfraTrust says one of the most important trends was the growing number of high-severity flaws affecting infrastructure management platforms.
These systems configure and control network devices, making them high-value targets. A successful compromise can give attackers extensive control over connected infrastructure, credentials, and administrative functions.
“For the second month in a row, the highest-value flaws exploited in infrastructure were in management software, so these platforms must be treated as high-value targets and patched, monitored, and hardened accordingly,” the report says.
Attackers target network infrastructure management systems
One of the most severe vulnerabilities highlighted in the report is CVE-2026-20079, a maximum-severity authentication bypass in Cisco Secure Firewall Management Center (FMC).
The flaw allows an unauthenticated attacker to send specially crafted HTTP requests to the FMC web interface and execute scripts or commands as root on a vulnerable device.
Cisco confirmed on September 9 that CVE-2026-20079 was being actively exploited. The company also updated its advisory to state that its Product Security Incident Response team was aware of attacks in August. On the same day, CISA added the vulnerability to its KEV Catalog.
However, BleepingComputer reported on July 29 that Cisco had already updated the CVE-2026-20079 advisory with hotfixes and indicators of compromise linked to attacks exploiting another FMC vulnerability, CVE-2026-20316.
At the time, Cisco said it was not aware of malicious exploitation of CVE-2026-20079, even though it published the same /var/tmp/license.tmp indicator for both vulnerabilities.
It was later confirmed that the two FMC vulnerabilities were exploited in a cascading attack chain.
Cisco Talos has associated the activity with three threat clusters tracked as UAT-12197, UAT-11823, and UAT-11988. The clusters include state-sponsored attackers and ransomware groups.
Attackers were observed using built-in FMC tools to conduct reconnaissance, deploy tunneling utilities, retrieve credentials from compromised systems, and, in some cases, deploy the Qilin ransomware encryption program.
Sophos’ Counter Threat Unit also analyzed a Linux implant named timezone_check recovered from a compromised FMC appliance. Researchers identified it as a variant of Cyclops Blink, malware previously associated with the Sandworm threat group.
Cisco separately disclosed six additional FMC vulnerabilities on September 16, including a flaw affecting the sftunnel connection that FMC uses to communicate with managed firewalls.
Cisco ISE authentication bypass exploited in attacks
Cisco’s Identity Services Engine (ISE) also contained multiple critical vulnerabilities.
On September 16, Cisco published an ISE advisory covering three vulnerabilities with a maximum CVSS score of 10.0.
One of them, CVE-2026-76460, is an authentication bypass affecting the API. It allows an unauthenticated remote attacker to execute commands as root.
Because the flaw was already being exploited, CISA added it to the KEV Catalog on the same day Cisco disclosed it.
Cisco says remote exploitation can be prevented by restricting access to the appliance with infrastructure access control lists. However, there is no workaround for the vulnerability.
InfraTrust says the trend extends beyond Cisco. During the reporting period, critical vulnerabilities also affected management platforms from:
- HPE Fabric Composer
- HPE EdgeConnect SD-WAN Orchestrator
- NVIDIA Unified Fabric Manager
- Dell SmartFabric Manager
- SonicWall NSM On-Prem
- Arista
“None of these are firewalls, switches, routers, or fabrics,” the report says.
“Each is a console that configures them, holds their credentials, and provides a change control path to them all at once.”
More critical infrastructure vulnerabilities
The report also highlights two vulnerabilities in SonicWall SMA 1000 appliances that were actively exploited and chained together.
CVE-2026-83548 is a CVSS 10.0 unauthenticated server-side request forgery vulnerability in the appliance workplace interface. CVE-2026-83549 is an operating system command injection vulnerability in the appliance management console.
According to InfraTrust, the flaws could be chained to achieve unauthenticated remote code execution.
CISA added both vulnerabilities to the KEV Catalog on September 2, and SonicWall confirmed that they were being exploited in attacks.
Rather than attempting to clean up a compromised installation, SonicWall recommends that customers install the latest hotfix, inspect systems for signs of compromise, and reimage physical appliances or redeploy virtual appliances.
Check Point discloses three critical VPN and management flaws
Check Point also disclosed three critical vulnerabilities that can be exploited remotely without authentication.
These include CVE-2026-85102, an authentication bypass that could lead to remote code execution in remote access and site-to-site VPNs, and CVE-2026-85103, a memory corruption vulnerability that could also lead to remote code execution.
The Dutch National Cyber Security Center (NCSC) warned of an impending exploit and urged administrators to install available security updates.
The third vulnerability, CVE-2026-91843, affects the unauthenticated login process and could allow an attacker to execute code as root on multiple Check Point management and logging servers.
Arista and Cisco Nexus vulnerabilities expose network devices
Arista published 34 security advisories, including two maximum-severity vulnerabilities that could allow unauthenticated remote code execution on EOS systems.
CVE-2026-73453 affects the P4Runtime service on TCP port 9559, while CVE-2026-73456 affects gNPSI.
Both features are disabled by default, and Arista says neither vulnerability is known to have been exploited.
InfraTrust also highlighted CVE-2026-20212, a critical vulnerability in Cisco Nexus 9000 switches. The flaw could allow an unauthenticated attacker to execute code as root through two debug ports that are reachable by default on affected switches.
One Linux kernel flaw appears in 19 infrastructure advisories
The September report demonstrates how vulnerabilities in third-party components can create widespread patching challenges across infrastructure products.
InfraTrust found that CVE-2026-31431, a Linux kernel privilege escalation vulnerability known as “CopyFail,” is currently listed in 19 separate security advisories from six vendors. CISA added the vulnerability to its KEV Catalog in May.
Arista, F5, Juniper, Extreme Networks, and HPE Aruba each issued advisories for products containing vulnerable components. Dell issued 14 advisories affecting products including VxRail, PowerFlex, ThinOS, PowerProtect, and Networking OS10.
“One upstream defect resulted in 19 remediation tasks, each arriving on a different vendor’s schedule and with a different advisory number,” InfraTrust explains.
UEFI Secure Boot bypass affects multiple vendors
The report also covers a UEFI Shell Secure Boot bypass discovered by Eclypsium and disclosed through CERT/CC.
The vulnerability allows an attacker with access to UEFI boot settings to launch the embedded UEFI shell, which would normally be blocked during the boot process.
From the UEFI shell, an attacker could modify Secure Boot settings in memory and execute unsigned code before the operating system starts.
The disclosure resulted in three vulnerability identifiers: CVE-2026-20293 for Cisco, CVE-2026-33197 for AMI Aptio-based systems, and CVE-2026-6485 for Insyde.
AMI, Dell, Cisco, Lenovo, and Supermicro have released or announced fixes for affected products.
Why infrastructure management systems require urgent attention
InfraTrust’s findings show why organizations should treat network management platforms, security consoles, and infrastructure controllers as high-priority assets. These systems often hold credentials and provide centralized control over firewalls, switches, routers, fabrics, and other critical devices.
Organizations should prioritize available patches and hotfixes, restrict management interfaces with access control lists, monitor for indicators of compromise, and reimage systems when vendors recommend that remediation step.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



