InfraTrust report warns network management systems under attack

Network Management Systems Under Siege as Attackers Exploit Critical Vulnerabilities

A recent report from Eclypsium’s InfraTrust Pulse has revealed that network management systems are increasingly being targeted by attackers, with devastating consequences. The monthly report tracks security advisories affecting various infrastructure components, and the latest edition paints a worrying picture of the vulnerability landscape.

Between August 25 and September 17, InfraTrust tracked an alarming 158 new security advisories across 17 vendors, covering a staggering 1,699 vulnerabilities. Of these, 42 were rated critical, with eight boasting a maximum CVSS score of 10.0, indicating that they can be exploited remotely without authentication. What’s more concerning is that five of the published advisories have made it onto CISA’s Known Exploited Vulnerabilities (KEV) catalog, highlighting the severity of the situation.

The most significant trend observed by InfraTrust is the targeting of management systems used to configure and control network devices. Attackers are compromising these systems to gain full control over compromised devices, essentially turning them into virtual backdoors for malicious activity. This is not a new phenomenon; in fact, it’s the second consecutive month where the highest-value exploited flaws have been found in administrative software.

One of the most critical vulnerabilities highlighted in the report is CVE-2026-20079, an authentication bypass flaw in Cisco Secure Firewall Management Center (FMC). An unauthenticated attacker can send crafted HTTP requests to the FMC web interface and execute scripts and commands as root on vulnerable devices. Cisco confirmed that this vulnerability was being actively exploited on September 9, updating its advisory to reflect this.

The attackers were observed using built-in FMC tools for reconnaissance, deploying tunneling utilities, harvesting credentials from compromised systems, and ultimately deploying Qilin ransomware encryptors. This activity has been linked to three threat clusters tracked by Cisco Talos, which include state-sponsored actors and ransomware gangs.

What’s particularly disturbing is that some of these vulnerabilities were exploited before or shortly after vendors disclosed them. This highlights the importance of timely patching and monitoring of management systems. InfraTrust emphasizes that infrastructure management platforms should be treated as high-value targets and patched accordingly.

The trend extends beyond Cisco, with vulnerabilities affecting HPE Fabric Composer, EdgeConnect SD-WAN Orchestrator, NVIDIA Unified Fabric Manager, Dell SmartFabric Manager, SonicWall NSM On-Prem, and Arista management interfaces. These systems are not typically thought of as security risks, but they provide a critical entry point for attackers.

In light of this report, it’s essential that organizations prioritize the security of their network management systems. Regular patching, monitoring, and hardening of these platforms can significantly reduce the risk of exploitation. It’s also crucial to implement robust access controls and restrict unnecessary access to sensitive areas of the network. By taking proactive measures, organizations can mitigate the risks associated with compromised management systems and protect their critical infrastructure from falling into the wrong hands.


Source: Bleeping Computer — 2026-09-23