Attackers Target Network Management Systems with Critical Vulnerabilities
InfraTrust has released its September report, highlighting a concerning trend in network management systems being targeted by attackers. The report notes that 158 new security advisories were tracked across 17 vendors, with 42 rated as critical and 71 allowing remote exploitation without authentication.
The most significant vulnerabilities are appearing in administrative software, used to configure and control network devices. This allows hackers to gain full control over compromised devices. InfraTrust warns that these platforms should be treated as high-value targets and patched accordingly.
Cisco's Secure Firewall Management Center (FMC) was hit with a maximum-severity authentication bypass vulnerability, CVE-2026-20079. The flaw allows an unauthenticated attacker to execute scripts and commands as root on vulnerable devices. Cisco confirmed that the vulnerability was being actively exploited and updated its advisory.
The trend extends beyond Cisco, with other vendors such as HPE Fabric Composer, EdgeConnect SD-WAN Orchestrator, NVIDIA Unified Fabric Manager, Dell SmartFabric Manager, SonicWall NSM On-Prem, and Arista management interfaces also affected. InfraTrust highlights the importance of patching and hardening these platforms to prevent exploitation.