Attackers are increasingly targeting the management systems used to configure and control enterprise infrastructure, according to the September edition of Eclypsium's InfraTrust Pulse.
Between August 25 and September 17, the report tracked 158 security advisories across 17 vendors, covering 1,699 vulnerabilities. Forty-two advisories were rated critical, eight had a maximum CVSS score of 10.0, 71 could be exploited remotely without authentication, and five included flaws later added to CISA's Known Exploited Vulnerabilities catalog.
InfraTrust said this was the second consecutive month in which the highest-value exploited infrastructure flaws were found in administrative software. One highlighted example, CVE-2026-20079, bypassed authentication in Cisco Secure Firewall Management Center and allowed unauthenticated attackers to execute scripts and commands as root. Cisco confirmed active exploitation on September 9, and CISA added the flaw to its catalog the same day. The flaw was later confirmed to have been chained with CVE-2026-20316.
The report said related attacks involved three threat clusters, UAT-12197, UAT-11823, and UAT-11988. Attackers used built-in tools, tunneling utilities, and credential theft, with some incidents ending in Qilin ransomware deployment. InfraTrust also highlighted critical issues in Cisco ISE and two SonicWall SMA 1000 vulnerabilities that could be chained for unauthenticated remote code execution.
Comments
0No comments yet. Be the first to comment.