Network management systems emerge as prime target as critical infrastructure flaws exploited

InfraTrust report flags surge in attacks on administrative software, including Cisco FMC zero-days chained by ransomware gangs and state-sponsored hackers

By LineZotpaper
Published
Read Time2 min
Attackers are increasingly targeting the enterprise network management platforms used to configure and control infrastructure devices, with several critical vulnerabilities being exploited before or shortly after disclosure, according to the September edition of Eclypsium's InfraTrust Pulse report.

The monthly report, which tracks security advisories affecting network devices, servers, firmware, and chips, found that between August 25 and September 17, 17 vendors published 158 advisories covering 1,699 vulnerabilities. Of those, 42 were rated critical, eight had a maximum CVSS score of 10.0, and 71 could be exploited remotely without authentication. Five advisories included vulnerabilities that were later added to CISA's Known Exploited Vulnerabilities (KEV) catalog.

The report's key finding is a trend: the most dangerous vulnerabilities are increasingly found in administrative software—the management systems used to configure and control network devices. Compromising these platforms gives attackers full control over the devices they manage.

"This is the second consecutive month the highest-value exploited flaws in infrastructure were in administrative software, so treat these platforms as high-value targets and patch, monitor, and harden them accordingly," the report states.

One of the most serious examples is CVE-2026-20079, a maximum-severity authentication bypass in Cisco Secure Firewall Management Center (FMC). The flaw allows an unauthenticated attacker to send crafted HTTP requests to the FMC web interface and execute scripts and commands as root on vulnerable devices.

Cisco confirmed on September 9 that the vulnerability was being actively exploited, updating its advisory after its Product Security Incident Response Team became aware of attacks in August. CISA added the flaw to its KEV catalog the same day.

However, Cisco had already updated the advisory on July 29 with hot fixes and indicators of compromise that were also associated with attacks exploiting another FMC vulnerability, CVE-2026-20316. At the time, Cisco said it was not aware of malicious exploitation of CVE-2026-20079, despite publishing the same /var/tmp/license.tmp indicator for both flaws.

The two FMC vulnerabilities were later confirmed to have been chained together in attacks. Cisco Talos linked the activity to three threat clusters—UAT-12197, UAT-11823, and UAT-11988—which include state-sponsored actors and ransomware gangs. The attackers used built-in FMC tools for reconnaissance, deployed tunneling utilities, harvested credentials from compromised systems, and in some cases ultimately deployed Qilin ransomware encryptors.

§

Analysis

Why This Matters

  • Network management systems are high-value targets: compromising them gives attackers control over entire fleets of devices, amplifying the impact of a single breach.
  • The trend of vulnerabilities being exploited before or shortly after disclosure suggests attackers are closely tracking vendor patches and racing to exploit gaps.
  • Organizations may need to prioritize hardening and monitoring of administrative software, not just edge devices, to reduce risk.

Background

Network management platforms, such as Cisco's Secure Firewall Management Center, are used by enterprises to centrally configure, monitor, and update network devices like firewalls and routers. Because these systems have privileged access to the devices they manage, they are attractive targets for attackers seeking to take over infrastructure. The InfraTrust Pulse report is a monthly aggregation of security advisories from vendors, tracking vulnerabilities across infrastructure components.

Key Perspectives

InfraTrust/Eclypsium: Emphasize that administrative software is now the highest-value target for infrastructure attacks, urging organizations to treat these platforms as critical assets. Cisco: Initially stated it was not aware of exploitation of CVE-2026-20079, but later confirmed active exploitation. The company has published hot fixes and indicators of compromise. Security researchers (e.g., Sophos Count): The chaining of vulnerabilities and involvement of ransomware and state-sponsored actors highlight the severity and sophistication of the threat.

What to Watch

  • Whether CISA adds more infrastructure management vulnerabilities to its KEV catalog in the coming weeks.
  • Whether additional vendors patch similar administrative software flaws before exploitation becomes widespread.
  • The evolution of the threat clusters UAT-12197, UAT-11823, and UAT-11988, and whether they shift to other management platforms.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.