Skip to content

Security1 publisher2 min readPublished

Eclypsium finds the month's exploited infrastructure flaws again in the management consoles

Eclypsium tracked 158 infrastructure advisories between August 25 and September 17. The exploited maximum-severity flaws it highlights are authentication bypasses in Cisco's Firewall Management Center and Identity Services Engine.

The Watch · Security desk

Illustration accompanying Eclypsium finds the month's exploited infrastructure flaws again in the management consoles

What happened

  • Eclypsium's September InfraTrust Pulse tracked 158 new advisories across 17 vendors covering 1,699 vulnerabilities between August 25 and September 17, with 42 rated critical and eight at a CVSS of 10.0.
  • CVE-2026-20079 lets an unauthenticated attacker send crafted HTTP requests to the Cisco Secure Firewall Management Center web interface and execute scripts and commands as root on the appliance.
  • Cisco Talos linked the FMC intrusions to three clusters, UAT-12197, UAT-11823 and UAT-11988, spanning state-sponsored actors and ransomware gangs that in some cases deployed Qilin encryptors.
  • Cisco disclosed three Identity Services Engine flaws scoring 10.0 on September 16, and CISA added the API authentication bypass CVE-2026-76460 to KEV the same day because it was already being exploited.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure An attacker with root on FMC or ISE holds the stored credentials and the change-control path for every device those consoles manage, so the blast radius is the managed fleet and not one appliance.
  • constraint For the exploited ISE bypass there is nothing to configure around it; Cisco offers infrastructure access control lists in front of the appliance as the only way to stop remote exploitation short of patching.
  • decision A patch queue ordered by internet-facing edge boxes puts the internal management platforms late, and for two months running those platforms are where the exploited flaws have been.

The two FMC flaws were used together. CVE-2026-20079 and CVE-2026-20316 were later confirmed to have been chained in attacks [10]. Once on the appliance, the operators ran reconnaissance with FMC's own built-in tooling, deployed tunneling utilities and harvested credentials from the compromised systems [12]. Sophos Counter Threat Unit recovered a Linux implant named timezone_check from compromised FMC appliances and identified it as a variant of Cyclops Blink, malware previously associated with Sandworm [13].

The dates on CVE-2026-20079 run in one direction. By July 29 Cisco had already updated the advisory with hot fixes and indicators of compromise that were also associated with attacks exploiting CVE-2026-20316 [8]. Cisco said at that point it was not aware of malicious exploitation of 20079, while publishing the same `/var/tmp/license.tmp` indicator for both [9]. Confirmation came on September 9, when Cisco said its Product Security Incident Response Team had become aware of the attacks in August [7]. Forty-two days separate the two statements [1].

Cisco disclosed six more FMC vulnerabilities on September 16, including flaws affecting the sftunnel connection FMC uses to communicate with managed firewalls [14].

The same reporting period brought vulnerabilities in HPE Fabric Composer, EdgeConnect SD-WAN Orchestrator, NVIDIA Unified Fabric Manager, Dell SmartFabric Manager, SonicWall NSM On-Prem and Arista management interfaces [18]. The report does not record exploitation for that group. "None of those is a firewall, switch, router, or fabric," the report said [19]. "Each one is the console that configures them, holds their credentials, and provides a change-control path into all of them at once" [20].

Of the 158 advisories, 71 were remotely exploitable without authentication, about 45 percent [3][2]. Five produced entries on CISA's Known Exploited Vulnerabilities catalog, roughly 3 percent of the month's volume [4][3]. At least two of those five were authentication bypasses in a management platform, the FMC flaw and the ISE API flaw [4]. "This is the second consecutive month the highest-value exploited flaws in infrastructure were in administrative software, so treat these platforms as high-value targets and patch, monitor, and harden them accordingly," the report said [5].

What to watch

  • Whether the three unnamed KEV entries from the August 25 to September 17 window are management platforms or edge devices.
  • Whether Sophos or Cisco ties the timezone_check implant to a specific Sandworm operation rather than a Cyclops Blink lineage.
  • Whether the HPE, NVIDIA, Dell, SonicWall and Arista console flaws show confirmed exploitation in the next InfraTrust edition.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories