Skip to content

Build1 publisher2 min readPublished

ZoomEye's fingerprint for Cisco's exploited FMC bypass returned zero hosts

A single September 2026 KEV batch produced 1,262,273 GitLab matches and nothing at all for Cisco Secure Firewall Management Center, because the console holding one of the two 10.0 bugs is the one passive scanning cannot fingerprint.

The Engineer · Build desk

Illustration accompanying ZoomEye's fingerprint for Cisco's exploited FMC bypass returned zero hosts

What happened

  • CVE-2026-85706, an unauthenticated arbitrary file read in GitLab's repository commits API scored CVSS 10.0, was fixed on 10 September 2026 and added to CISA's Known Exploited Vulnerabilities catalog the next day.
  • That batch also includes a pre-authentication authentication bypass in Cisco Secure Firewall Management Center rated 10.0, plus a 5.3 static credential flaw, both exploited by three clusters tracked by Cisco Talos.
  • CVE-2026-59822, an authentication bypass in BerriAI LiteLLM's MCP Streamable HTTP endpoint, was fixed in release 1.84.0 and carried a KEV deadline of 16 September 2026.
  • The Cisco Secure Firewall Management Center fingerprint returned zero matches in the same run, and a page title query for "Firewall Management Center" returned a single host.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint External measurement only helps where a service advertises itself, so the FMC bypass has to be inventoried from internal records and discovery while GitLab can be checked from outside.
  • decision The output of an external scan that changes a work queue is the reconciliation list: hosts visible outside with no internal record are the ones most likely to sit outside the patch process, and each still needs a version check.
  • exposure The September additions cluster on internet-reachable services that hold credentials or control other systems, so the observable GitLab and LiteLLM populations are hosts with secrets on them.

Passive fingerprinting matches identifying content in a response: banner strings and page titles. GitLab publishes enough of it to be counted at scale, and so does LiteLLM [11]. A Firewall Management Center login page publishes very little, and the console normally sits behind a VPN or a jump host [11]. Cisco Talos ties CVE-2026-20079 to three exploitation clusters, so the zero is a fact about visibility [4][12].

The GitLab fingerprint returned 1,262,273 matches in ZoomEye's IPv4 device dataset and 52,074 in its web dataset on the same day, a factor of about 24 [8][1]. The post does not explain how the two datasets differ. Anyone quoting an exposure figure for this batch needs to say which query and which dataset produced it.

Neither figure describes any one estate. According to the post, a match means the service was observed at that address, not that the version is affected or that the vulnerable endpoint is reachable, and the counts treat a deliberately published service and an accidentally exposed one alike [18].

KEV timing inside the batch varies by weeks. GitLab's fix landed on 10 September 2026 and the CVE was catalogued the next day [3]. SharePoint's CVE-2026-56164 was fixed in July 2026 and added on 15 September, roughly two months later [6][3]. LiteLLM's entry carried a 16 September deadline, three days before the queries that found 34,402 instances of it [5][9][4].

The counts come from one measurement service, queried on 19 September 2026, in a post that also recommends ZoomEye's attack surface management capability for assets a passive scan never registers; the post describes that capability as taking an organisation's own asset clues and continuously discovering associated assets [8][16].

The reachability question does not apply to two entries in the batch. CVE-2026-85880 and CVE-2026-81963 are both rated 7.8 and sit in the ALPC and Windows Update Stack components [7]. Those components are present on nearly every host. The post's argument for their weight is position: they are used to move from a foothold to control [17].

What to watch

  • A second measurement service reproducing the 19 September counts; a wide gap would mean the fingerprints differ, not the populations.
  • Whether later KEV batches keep adding management-plane bugs that passive scanning cannot see, making internal discovery the only evidence available.
  • Exploitation telemetry for CVE-2026-85706 from GitLab, which would show how much of the observed population was actually reached.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories