Network Management System Attacks Skyrocket as Attackers Target Administrative Software
InfraTrust, a leading provider of security advisories for infrastructure devices, has published its September report highlighting a concerning trend in network management system attacks.
The report notes that attackers are increasingly targeting administrative software used to configure and control network devices, giving hackers full control over compromised devices. This trend extends beyond Cisco, with vulnerabilities affecting HPE Fabric Composer, EdgeConnect SD-WAN Orchestrator, NVIDIA Unified Fabric Manager, Dell SmartFabric Manager, SonicWall NSM On-Prem, and Arista management interfaces.
The report specifically highlights CVE-2026-20079, a maximum-severity Cisco Secure Firewall Management Center (FMC) authentication bypass vulnerability that allows unauthenticated attackers to execute scripts and commands as root on vulnerable devices. This flaw was actively exploited before Cisco disclosed it, with the vendor confirming attacks in August.
InfraTrust warns that administrative software should be treated as high-value targets and patched accordingly. The report also highlights two actively exploited SonicWall SMA 1000 vulnerabilities that were chained together in attacks, as well as critical vulnerabilities affecting Check Point management and logging servers.