Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Asphalt Company Alleges Operative Who Posed as a Project Opponent Committed Fraud

    September 23, 2026

    Expro lines up 14-well Canadian offshore life-extension campaign

    September 23, 2026

    Could we be about to see the end of northern English dialects? My experience – and the science – says aye | Zahaan Bharmal

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Asphalt Company Alleges Operative Who Posed as a Project Opponent Committed Fraud
    • Expro lines up 14-well Canadian offshore life-extension campaign
    • Could we be about to see the end of northern English dialects? My experience – and the science – says aye | Zahaan Bharmal
    • Labour by-election candidate has British nationality, contrary to social media claims – Full Fact
    • Thélyson Orélien: French uproar over author accused of using AI
    • Disgraced Hollywood mogul Harvey Weinstein sentenced to 15 years for 2006 sex assault
    • Badenoch registers gift of £8,177 for Murdoch meeting
    • Six arrested after anti-migrant protest at Gosport marina | Police
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    InfraTrust report warns network management systems under attack

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 23, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them.

    This was reported in the September edition of Eclypsium’s InfraTrust Pulse, a monthly report tracking security advisories affecting network devices, servers, firmware, chips, and other infrastructure.

    Between August 25 and September 17, InfraTrust tracked 158 new security advisories across 17 vendors, covering 1,699 vulnerabilities.

    Of those advisories, 42 were rated critical, eight had a maximum CVSS score of 10.0, and 71 could be exploited remotely without authentication.

    Five of the published advisories included vulnerabilities that ultimately made it on to CISA’s Known Exploited Vulnerabilities (KEV) catalog.

    However, InfraTrust says one of the more significant trends this month is where many of the most dangerous vulnerabilities are appearing.

    Attackers are increasingly compromising the management systems used to configure and control network devices, giving hackers full control over compromised devices.

    “This is the second consecutive month the highest-value exploited flaws in infrastructure were in administrative software, so treat these platforms as high-value targets and patch, monitor, and harden them accordingly,” reads the report.

    Infrastructure management systems targeted

    One of the most serious vulnerabilities highlighted in the report is CVE-2026-20079, a maximum-severity Cisco Secure Firewall Management Center (FMC) authentication bypass.

    The flaw allows an unauthenticated attacker to send crafted HTTP requests to the FMC web interface and execute scripts and commands as root on vulnerable devices.

    Cisco confirmed on September 9 that the vulnerability was being actively exploited, updating its advisory to say its Product Security Incident Response Team became aware of the attacks in August. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog the same day.

    However, BleepingComputer previously reported on July 29 that Cisco had already updated the CVE-2026-20079 advisory with hot fixes and indicators of compromise that were also associated with attacks exploiting another FMC vulnerability, CVE-2026-20316.

    At the time, Cisco said it was not aware of malicious exploitation of CVE-2026-20079, despite publishing the same `/var/tmp/license.tmp` indicator for both vulnerabilities.

    The two FMC flaws were later confirmed to have been chained together in attacks.

    Cisco Talos has linked the activity to three threat clusters tracked as UAT-12197, UAT-11823, and UAT-11988, which include state-sponsored actors and ransomware gangs.

    The attackers were observed using built-in FMC tools for reconnaissance, deploying tunneling utilities, harvesting credentials from compromised systems, and in some cases, ultimately deploying Qilin ransomware encryptors.

    Sophos Counter Threat Unit also analyzed a Linux implant named “timezone_check” recovered from compromised FMC appliances and identified it as a variant of Cyclops Blink, malware previously associated with the Sandworm threat group.

    Cisco separately disclosed six additional FMC vulnerabilities on September 16, including flaws affecting the sftunnel connection FMC uses to communicate with managed firewalls.

    Cisco Identity Services Engine (ISE), another management platform, was also hit with multiple critical vulnerabilities.

    Cisco disclosed ISE advisories on September 16, including three vulnerabilities with maximum CVSS scores of 10.0.

    One of them, CVE-2026-76460, is an authentication bypass in an API that allows an unauthenticated remote attacker to execute commands as root.

    CISA added the flaw to the KEV catalog on the same day Cisco disclosed it as it was already exploited in attacks.

    Cisco says there are no workarounds, although restricting access to the appliance using infrastructure access control lists can prevent remote exploitation.

    InfraTrust says this trend extends beyond Cisco.

    During the September reporting period, vulnerabilities also affected HPE Fabric Composer, EdgeConnect SD-WAN Orchestrator, NVIDIA Unified Fabric Manager, Dell SmartFabric Manager, SonicWall NSM On-Prem, and Arista management interfaces.

    “None of those is a firewall, switch, router, or fabric,” the report says.

    “Each one is the console that configures them, holds their credentials, and provides a change-control path into all of them at once.”

    More critical infrastructure flaws

    The report also highlights two actively exploited SonicWall SMA 1000 vulnerabilities that were chained together in attacks.

    CVE-2026-83548 is a CVSS 10.0 unauthenticated server-side request forgery vulnerability in the Appliance Work Place interface and CVE-2026-83549 is an OS command injection vulnerability in the Appliance Management Console.

    InfraTrust says the flaws can be chained to achieve unauthenticated remote code execution.

    CISA added both vulnerabilities to its KEV catalog on September 2, and SonicWall has confirmed they are being exploited in attacks.

    The vendor recommends that customers upgrade to the latest hotfix, investigate systems for signs of compromise, and re-image physical appliances or redeploy virtual ones rather than attempting to clean compromised installations in place.

    Check Point also disclosed three critical, remotely exploitable vulnerabilities that require no authentication.

    These include CVE-2026-85102, an authentication bypass that can lead to remote code execution in Remote Access and Site-to-Site VPN, and CVE-2026-85103, a memory corruption vulnerability that can also lead to remote code execution.

    The Dutch Nationaal Cyber Security Centrum (NCSC) urged admins to install security updates, warning that exploitation was imminent.

    A third vulnerability, CVE-2026-91843, is a a vulnerability in the unauthenticated login process that can allow attackers to execute code as root on several Check Point management and logging servers.

    Arista published 34 security advisories on September 9, including two maximum-severity vulnerabilities that can allow unauthenticated remote code execution on EOS systems.

    CVE-2026-73453 affects the P4Runtime service on TCP port 9559, while CVE-2026-73456 affects gNPSI.

    Both features are disabled by default, and Arista says neither vulnerability is known to have been exploited.

    InfraTrust also highlighted CVE-2026-20212, a critical Cisco Nexus 9000 vulnerability that can allow unauthenticated attackers to gain root code execution through two debug ports that are reachable by default on affected switches.

    One Linux flaw spreads across 19 advisories

    The September report also shows how supply-chain vulnerabilities in third-party components can create patching headaches across infrastructure products.

    InfraTrust found that CVE-2026-31431, a Linux kernel privilege escalation vulnerability dubbed “CopyFail” and added to CISA’s KEV catalog in May, now appears in 19 separate security advisories from six vendors.

    Arista, F5, Juniper, Extreme Networks, and HPE Aruba each published an advisory affecting products that contain the vulnerable component, while Dell accounts for 14 advisories covering products including VxRail, PowerFlex, ThinOS, PowerProtect, and Networking OS10.

    “One upstream defect created nineteen remediation tasks, each arriving on a different vendor schedule with a different advisory number,” the report explains.

    Firmware remains another weak point

    The report also mentions a UEFI Shell Secure Boot bypass discovered by Eclypsium and disclosed through CERT/CC.

    The vulnerability allows an attacker with access to UEFI boot settings to launch an embedded UEFI Shell that is normally blocked during startup.

    From there, the attacker can modify Secure Boot settings in memory and run unsigned code before the operating system starts.

    The disclosure resulted in three vulnerabilities tracked as CVE-2026-20293 for Cisco, CVE-2026-33197 for AMI Aptio-based systems, and CVE-2026-6485 for Insyde.

    AMI, Dell, Cisco, Lenovo, and Supermicro have released or announced fixes for affected products.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    attack InfraTrust management Network Report Systems warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

    Arista patches actively exploited VeloCloud Orchestrator zero-day

    Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

    Microsoft: September Windows updates break Always On VPN connections

    D-Link warns of max severity zero-day bug in DIR-822A routers

    F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Asphalt Company Alleges Operative Who Posed as a Project Opponent Committed Fraud

    September 23, 2026

    Expro lines up 14-well Canadian offshore life-extension campaign

    September 23, 2026

    Could we be about to see the end of northern English dialects? My experience – and the science – says aye | Zahaan Bharmal

    September 23, 2026

    Labour by-election candidate has British nationality, contrary to social media claims – Full Fact

    September 23, 2026
    Latest Posts

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    Uber CEO brushes off reports of a Waymo break-up

    August 5, 2026

    Fauci Faces Contempt Vote. Here Are the Legal Issues Involved.

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Asphalt Company Alleges Operative Who Posed as a Project Opponent Committed Fraud

    September 23, 2026

    Expro lines up 14-well Canadian offshore life-extension campaign

    September 23, 2026

    Could we be about to see the end of northern English dialects? My experience – and the science – says aye | Zahaan Bharmal

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.