InfraTrust report warns network management systems under attack

Network management vulnerabilities

Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them.

This was reported in the September edition of Eclypsium’s InfraTrust Pulse, a monthly report tracking security advisories affecting network devices, servers, firmware, chips, and other infrastructure.

Between August 25 and September 17, InfraTrust tracked 158 new security advisories across 17 vendors, covering 1,699 vulnerabilities.

Of those advisories, 42 were rated critical, eight had a maximum CVSS score of 10.0, and 71 could be exploited remotely without authentication.

Five of the published advisories included vulnerabilities that ultimately made it on to CISA’s Known Exploited Vulnerabilities (KEV) catalog.

However, InfraTrust says one of the more significant trends this month is where many of the most dangerous vulnerabilities are appearing.

Attackers are increasingly compromising the management systems used to configure and control network devices, giving hackers full control over compromised devices.

“This is the second consecutive month the highest-value exploited flaws in infrastructure were in administrative software, so treat these platforms as high-value targets and patch, monitor, and harden them accordingly,” reads the report.

Infrastructure management systems targeted

One of the most serious vulnerabilities highlighted in the report is CVE-2026-20079, a maximum-severity Cisco Secure Firewall Management Center (FMC) authentication bypass.

The flaw allows an unauthenticated attacker to send crafted HTTP requests to the FMC web interface and execute scripts and commands as root on vulnerable devices.

Cisco confirmed on September 9 that the vulnerability was being actively exploited, updating its advisory to say its Product Security Incident Response Team became aware of the attacks in August. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog the same day.

However, BleepingComputer previously reported on July 29 that Cisco had already updated the CVE-2026-20079 advisory with hot fixes and indicators of compromise that were also associated with attacks exploiting another FMC vulnerability, CVE-2026-20316.

At the time, Cisco said it was not aware of malicious exploitation of CVE-2026-20079, despite publishing the same `/var/tmp/license.tmp` indicator for both vulnerabilities.

The two FMC flaws were later confirmed to have been chained together in attacks.

Cisco Talos has linked the activity to three threat clusters tracked as UAT-12197, UAT-11823, and UAT-11988, which include state-sponsored actors and ransomware gangs.

The attackers were observed using built-in FMC tools for reconnaissance, deploying tunneling utilities, harvesting credentials from compromised systems, and in some cases, ultimately deploying Qilin ransomware encryptors.

Sophos Counter Threat Unit also analyzed a Linux implant named “timezone_check” recovered from compromised FMC appliances and identified it as a variant of Cyclops Blink, malware previously associated with the Sandworm threat group.

Cisco separately disclosed six additional FMC vulnerabilities on September 16, including flaws affecting the sftunnel connection FMC uses to communicate with managed firewalls.

Cisco Identity Services Engine (ISE), another management platform, was also hit with multiple critical vulnerabilities.

Cisco disclosed ISE advisories on September 16, including three vulnerabilities with maximum CVSS scores of 10.0.

One of them, CVE-2026-76460, is an authentication bypass in an API that allows an unauthenticated remote attacker to execute commands as root.

CISA added the flaw to the KEV catalog on the same day Cisco disclosed it as it was already exploited in attacks.

Cisco says there are no workarounds, although restricting access to the appliance using infrastructure access control lists can prevent remote exploitation.

InfraTrust says this trend extends beyond Cisco.

During the September reporting period, vulnerabilities also affected HPE Fabric Composer, EdgeConnect SD-WAN Orchestrator, NVIDIA Unified Fabric Manager, Dell SmartFabric Manager, SonicWall NSM On-Prem, and Arista management interfaces.

“None of those is a firewall, switch, router, or fabric,” the report says.

“Each one is the console that configures them, holds their credentials, and provides a change-control path into all of them at once.”

More critical infrastructure flaws

The report also highlights two actively exploited SonicWall SMA 1000 vulnerabilities that were chained together in attacks.

CVE-2026-83548 is a CVSS 10.0 unauthenticated server-side request forgery vulnerability in the Appliance Work Place interface and CVE-2026-83549 is an OS command injection vulnerability in the Appliance Management Console.

InfraTrust says the flaws can be chained to achieve unauthenticated remote code execution.

CISA added both vulnerabilities to its KEV catalog on September 2, and SonicWall has confirmed they are being exploited in attacks.

The vendor recommends that customers upgrade to the latest hotfix, investigate systems for signs of compromise, and re-image physical appliances or redeploy virtual ones rather than attempting to clean compromised installations in place.

Check Point also disclosed three critical, remotely exploitable vulnerabilities that require no authentication.

These include CVE-2026-85102, an authentication bypass that can lead to remote code execution in Remote Access and Site-to-Site VPN, and CVE-2026-85103, a memory corruption vulnerability that can also lead to remote code execution.

The Dutch Nationaal Cyber Security Centrum (NCSC) urged admins to install security updates, warning that exploitation was imminent.

A third vulnerability, CVE-2026-91843, is a a vulnerability in the unauthenticated login process that can allow attackers to execute code as root on several Check Point management and logging servers.

Arista published 34 security advisories on September 9, including two maximum-severity vulnerabilities that can allow unauthenticated remote code execution on EOS systems.

CVE-2026-73453 affects the P4Runtime service on TCP port 9559, while CVE-2026-73456 affects gNPSI.

Both features are disabled by default, and Arista says neither vulnerability is known to have been exploited.

InfraTrust also highlighted CVE-2026-20212, a critical Cisco Nexus 9000 vulnerability that can allow unauthenticated attackers to gain root code execution through two debug ports that are reachable by default on affected switches.

One Linux flaw spreads across 19 advisories

The September report also shows how supply-chain vulnerabilities in third-party components can create patching headaches across infrastructure products.

InfraTrust found that CVE-2026-31431, a Linux kernel privilege escalation vulnerability dubbed “CopyFail” and added to CISA’s KEV catalog in May, now appears in 19 separate security advisories from six vendors.

Arista, F5, Juniper, Extreme Networks, and HPE Aruba each published an advisory affecting products that contain the vulnerable component, while Dell accounts for 14 advisories covering products including VxRail, PowerFlex, ThinOS, PowerProtect, and Networking OS10.

“One upstream defect created nineteen remediation tasks, each arriving on a different vendor schedule with a different advisory number,” the report explains.

Firmware remains another weak point

The report also mentions a UEFI Shell Secure Boot bypass discovered by Eclypsium and disclosed through CERT/CC.

The vulnerability allows an attacker with access to UEFI boot settings to launch an embedded UEFI Shell that is normally blocked during startup.

From there, the attacker can modify Secure Boot settings in memory and run unsigned code before the operating system starts.

The disclosure resulted in three vulnerabilities tracked as CVE-2026-20293 for Cisco, CVE-2026-33197 for AMI Aptio-based systems, and CVE-2026-6485 for Insyde.

AMI, Dell, Cisco, Lenovo, and Supermicro have released or announced fixes for affected products.

article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat