Exploited Management Systems: A Critical Threat to Enterprise Infrastructure
Attackers are increasingly targeting the very systems designed to manage enterprise infrastructure, exploiting critical vulnerabilities in platforms like Cisco FMC and ISE, as well as products from SonicWall, Check Point, and others. A new report from **Eclypsium's InfraTrust Pulse** reveals a surge in high-value flaws within administrative software, underscoring a pressing need for immediate patching and heightened security measures.
Cybersecurity professionals are facing a rapidly evolving threat landscape, with a significant shift towards exploiting infrastructure management systems. The latest **InfraTrust Pulse** report, covering the period between August 25 and September 17, tracked 158 new security advisories across 17 vendors, affecting 1,699 vulnerabilities. Of these, 42 were rated critical, eight boasted a maximum **CVSS** score of 10.0, and 71 could be exploited remotely without authentication.
Crucially, five of the vulnerabilities highlighted in the report have already made it onto **CISA's Known Exploited Vulnerabilities (KEV)** catalog, indicating active exploitation in the wild.
## Management Systems Under Siege
For the second consecutive month, **InfraTrust** emphasizes that the most dangerous exploited flaws are found in administrative software. These platforms, which configure and control network devices, offer attackers full control once compromised.
"This is the second consecutive month the highest-value exploited flaws in infrastructure were in administrative software, so treat these platforms as high-value targets and patch, monitor, and harden them accordingly," the report states.
### Cisco's Management Platforms Targeted
Among the most severe vulnerabilities is **CVE-2026-20079**, a maximum-severity authentication bypass in **Cisco Secure Firewall Management Center (FMC)**. This flaw allows unauthenticated attackers to send crafted HTTP requests, executing scripts and commands as root. **Cisco** confirmed active exploitation on September 9, with **CISA** adding it to the **KEV** catalog the same day.
Earlier reports indicated that **CVE-2026-20079** and another **FMC** vulnerability, **CVE-2026-20316**, were being chained together in attacks. **Cisco Talos** has linked this activity to three threat clusters (**UAT-12197**, **UAT-11823**, and **UAT-11988**), including state-sponsored actors and ransomware gangs. Attackers leveraged built-in **FMC** tools for reconnaissance, deployed tunneling utilities, harvested credentials, and in some cases, deployed **Qilin ransomware** encryptors.
**Sophos Counter Threat Unit** also identified a Linux implant dubbed "timezone_check" on compromised **FMC** appliances, linking it to a variant of **Cyclops Blink** malware, previously associated with the **Sandworm** threat group.
**Cisco Identity Services Engine (ISE)**, another critical management platform, was also impacted by multiple severe vulnerabilities. Advisories released on September 16 included three flaws with maximum **CVSS** scores of 10.0. One of these, **CVE-2026-76460**, is an authentication bypass in an API, enabling unauthenticated remote attackers to execute commands as root. This flaw was added to the **KEV** catalog immediately upon disclosure due to active exploitation.
### Beyond Cisco: Widespread Management System Vulnerabilities
The trend of targeting management systems extends beyond **Cisco**. The September reporting period saw critical vulnerabilities affecting:
* **HPE Fabric Composer**
* **EdgeConnect SD-WAN Orchestrator**
* **NVIDIA Unified Fabric Manager**
* **Dell SmartFabric Manager**
* **SonicWall NSM On-Prem**
* **Arista** management interfaces
"None of those is a firewall, switch, router, or fabric," the report emphasizes. "Each one is the console that configures them, holds their credentials, and provides a change-control path into all of them at once."
## More Critical Infrastructure Flaws
The report also highlights other significant vulnerabilities:
* **SonicWall SMA 1000**: Two actively exploited vulnerabilities, **CVE-2026-83548** (CVSS 10.0 unauthenticated server-side request forgery) and **CVE-2026-83549** (OS command injection), were chained for unauthenticated remote code execution. Both are in the **KEV** catalog, and **SonicWall** recommends upgrading to the latest hotfix and re-imaging compromised appliances.
* **Check Point**: Three critical, remotely exploitable vulnerabilities requiring no authentication were disclosed. These include **CVE-2026-85102** (authentication bypass leading to RCE in VPNs), **CVE-2026-85103** (memory corruption leading to RCE), and **CVE-2026-91843** (vulnerability in the unauthenticated login process allowing root code execution on management servers). The **Dutch Nationaal Cyber Security Centrum (NCSC)** urged immediate patching.
* **Arista**: 34 security advisories were published, including two maximum-severity vulnerabilities (**CVE-2026-73453** and **CVE-2026-73456**) allowing unauthenticated remote code execution on **EOS** systems via **P4Runtime** and **gNPSI** services, respectively. These are disabled by default and not known to be exploited.
* **Cisco Nexus 9000**: **CVE-2026-20212**, a critical vulnerability, allows unauthenticated attackers to gain root code execution through two debug ports reachable by default.
## Supply Chain Headaches: One Flaw, Many Advisories
The report also underscores the challenge of supply chain vulnerabilities. **CVE-2026-31431**, a **Linux** kernel privilege escalation flaw dubbed "**CopyFail**" and added to **CISA's KEV** catalog in May, now appears in 19 separate security advisories from six vendors. This includes products from **Arista**, **F5**, **Juniper**, **Extreme Networks**, **HPE Aruba**, and 14 advisories from **Dell** alone.
"One upstream defect created nineteen remediation tasks, each arriving on a different vendor schedule with a different advisory number," the report highlights, showcasing the complexity of patching across diverse infrastructure.
## Firmware Remains a Weak Point
Finally, the report mentions a **UEFI Shell Secure Boot** bypass discovered by **Eclypsium** and disclosed through **CERT/CC**. This vulnerability allows an attacker with access to **UEFI** boot settings to launch an embedded **UEFI Shell**, circumventing secure boot protections.
