InfraTrust Report Warns Attackers Target Network Management Systems

Eclypsium's September InfraTrust Pulse report warns that attackers are increasingly targeting the management systems used to control enterprise infrastructure. Between August 25 and September 17, the report tracked 158 new security advisories from 17 vendors, covering 1,699 vulnerabilities. Of these, 42 are rated critical, eight score a maximum 10.0 CVSS, and 71 can be exploited remotely without authentication, with five advisories containing flaws added to CISA's Known Exploited Vulnerabilities catalog.

The most serious highlighted flaw is CVE-2026-20079, a maximum-severity authentication bypass in Cisco Secure Firewall Management Center that lets unauthenticated attackers execute commands as root via crafted HTTP requests. Cisco confirmed on September 9 that the vulnerability is being actively exploited, and CISA added it to its KEV catalog the same day. However, BleepingComputer reports Cisco had already published hot fixes and indicators of compromise as early as July 29, tied to attacks also involving a related flaw, CVE-2026-20316.

InfraTrust notes this is the second consecutive month in which the highest-value exploited flaws appear in administrative software rather than the devices themselves. Gaining access to management platforms gives attackers full control over compromised infrastructure, dramatically expanding their reach. The report urges organizations to treat these administrative platforms as high-value targets and to patch, monitor, and harden them accordingly.

Read More at the original source →