Cyberattacks on Network Management Systems Leave Enterprises Vulnerable to Devastating Consequences
A recent surge in targeted attacks against network management systems has left many enterprises scrambling to patch critical vulnerabilities, as malicious actors exploit weaknesses in these critical infrastructure components. According to a warning from InfraTrust, the latest edition of their monthly report tracking security advisories affecting network devices and servers, attackers are increasingly compromising the management systems used to configure and control network devices, giving hackers full control over compromised devices.
InfraTrust’s September report highlights 158 new security advisories across 17 vendors, covering a staggering 1,699 vulnerabilities. Of these, 42 were rated critical, with eight having a maximum CVSS score of 10.0. What’s more alarming is that 71 of these vulnerabilities can be exploited remotely without authentication, making it easier for attackers to gain access to sensitive systems.
One of the most significant trends observed in this month’s report is the targeting of administrative software used to manage network devices. InfraTrust emphasizes the importance of treating these platforms as high-value targets and urges administrators to patch, monitor, and harden them accordingly. This trend extends beyond Cisco, with vulnerabilities also affecting HPE Fabric Composer, EdgeConnect SD-WAN Orchestrator, NVIDIA Unified Fabric Manager, Dell SmartFabric Manager, SonicWall NSM On-Prem, and Arista management interfaces.
Cisco’s Secure Firewall Management Center (FMC) has been particularly vulnerable to attacks. InfraTrust highlights CVE-2026-20079, a maximum-severity authentication bypass vulnerability in FMC that allows an unauthenticated attacker to execute scripts and commands as root on vulnerable devices. Cisco confirmed that this vulnerability was being actively exploited, with their Product Security Incident Response Team becoming aware of the attacks in August. The flaw has since been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.
In some cases, attackers have chained together vulnerabilities in FMC to deploy malicious payloads, including Qilin ransomware encryptors and a variant of Cyclops Blink malware linked to the Sandworm threat group. Cisco has separately disclosed six additional FMC vulnerabilities on September 16, including flaws affecting the sftunnel connection used by managed firewalls.
InfraTrust’s warning serves as a stark reminder that network management systems are often overlooked in security efforts but pose significant risks if compromised. Enterprises must prioritize patching and hardening these critical components to prevent devastating consequences. By treating administrative software as high-value targets, administrators can significantly reduce the risk of falling victim to targeted attacks.
In light of this warning, we recommend that enterprise administrators:
* Regularly review InfraTrust’s monthly reports to stay informed about emerging threats
* Prioritize patching and hardening network management systems
* Restrict access to these platforms using infrastructure access control lists to prevent remote exploitation
* Monitor for signs of unauthorized activity in network devices
By taking proactive measures, enterprises can mitigate the risks associated with targeted attacks on network management systems and protect their sensitive data from falling into the wrong hands.
Source: Bleeping Computer — 2026-09-23