The monthly report, which tracks security advisories affecting network devices, servers, firmware, and chips, found that between August 25 and September 17, 17 vendors published 158 advisories covering 1,699 vulnerabilities. Of those, 42 were rated critical, eight had a maximum CVSS score of 10.0, and 71 could be exploited remotely without authentication. Five advisories included vulnerabilities that were later added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
The report's key finding is a trend: the most dangerous vulnerabilities are increasingly found in administrative software—the management systems used to configure and control network devices. Compromising these platforms gives attackers full control over the devices they manage.
"This is the second consecutive month the highest-value exploited flaws in infrastructure were in administrative software, so treat these platforms as high-value targets and patch, monitor, and harden them accordingly," the report states.
One of the most serious examples is CVE-2026-20079, a maximum-severity authentication bypass in Cisco Secure Firewall Management Center (FMC). The flaw allows an unauthenticated attacker to send crafted HTTP requests to the FMC web interface and execute scripts and commands as root on vulnerable devices.
Cisco confirmed on September 9 that the vulnerability was being actively exploited, updating its advisory after its Product Security Incident Response Team became aware of attacks in August. CISA added the flaw to its KEV catalog the same day.
However, Cisco had already updated the advisory on July 29 with hot fixes and indicators of compromise that were also associated with attacks exploiting another FMC vulnerability, CVE-2026-20316. At the time, Cisco said it was not aware of malicious exploitation of CVE-2026-20079, despite publishing the same /var/tmp/license.tmp indicator for both flaws.
The two FMC vulnerabilities were later confirmed to have been chained together in attacks. Cisco Talos linked the activity to three threat clusters—UAT-12197, UAT-11823, and UAT-11988—which include state-sponsored actors and ransomware gangs. The attackers used built-in FMC tools for reconnaissance, deployed tunneling utilities, harvested credentials from compromised systems, and in some cases ultimately deployed Qilin ransomware encryptors.