
The Cisco FMC and ISE perfect 10s are being exploited in the wild, and four vendors shipped fixes for the UEFI Shell Secure Boot bypass Eclypsium disclosed.
This is the third edition of InfraTrust Pulse, our monthly rundown of the security advisories that matter for the infrastructure running everything (such as network devices, servers, chips, firmware, and baseboard management controllers). The August edition closed on August 24, so this one picks up on August 25 and runs through September 17, 2026.
In that window, vendors we track published 158 new security advisories across 17 vendors, covering 1,699 distinct CVEs. Forty-two of those advisories are rated Critical by CVSS, and eight have a perfect CVSS score of 10.0. Seventy-one are remotely exploitable with no authentication, which I care about more than the score (and you should too). Five newly published advisories include a CVE on CISA’s exploited list, and 84 advisories were revised during the window without being newly published.

On September 9, CISA added CVE-2026-20079 to the Known Exploited Vulnerabilities catalog. On September 16, Cisco revised its own advisory (cisco-sa-onprem-fmc-authbypass-5JPp45V2) to version 2.5 and added a line that reads, in Cisco’s words, “In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.”
The flaw is rated Critical at a perfect CVSS 10.0. It allows an unauthenticated attacker to send crafted HTTP requests to the FMC web interface and gain root access on the underlying operating system. Every FMC release is affected. CISA published this CVE to the KEV list on September 9. Cisco’s own advisory didn’t say so until September 16, and Cisco hasn’t said which day in August their PSIRT found out, so the time from when they knew to when they said anything is somewhere between two and seven weeks. EPSS puts CVE-2026-20079 at 0.747, an estimated probability of exploitation activity of roughly 75% over the next 30 days. If you are waiting for the vendor or CISA to tell you about active exploitation before patching, you may be too late. For example, a CVSS 10.0 vulnerability providing an unauthenticated attacker root-level privileges is something you must patch right away, always.
Version 2.6 of the advisory, also dated September 16, replaced the hotfixes with the security hardening releases, so if you applied a hotfix in August, you are not done. Then Cisco published its September 16 bundle, and FMC got six more advisories in a single day.
The sftunnel vulnerabilities are interesting. sftunnel is the inter-device channel FMC uses to manage its firewalls; it’s enabled by default, and three of these six advisories are about it. CVE-2026-20324 turns a registered peer into root on the manager, and CVE-2026-20295 lets an unauthenticated attacker bypass sftunnel authentication. Chaining those two lets the attacker exploit the trust relationship between a firewall and its manager as an attack path.
What is actually happening on these boxes? Talos published its exploitation analysis on September 9, the same day CISA added CVE-2026-20079 to the KEV list. It describes three separate clusters of post-compromise activity on FMC instances, which Talos tracks as UAT-12197, UAT-11823, and UAT-11988. The clusters include both state-sponsored and crimeware actors, an unusual pairing to see on one appliance. Attackers use FMC’s built-in tooling for reconnaissance, deploy tunneling tools to maintain network access, and harvest credentials rather than bringing their own toolkit.
The implant is the part I find most interesting. Sophos Counter Threat Unit analyzed a 64-bit Linux executable named timezone_check pulled from multiple compromised FMC devices and identified it as a variant of Cyclops Blink, the modular implant analyzed in 2022 and publicly associated with Sandworm (also tracked as Seashell Blizzard and IRON VIKING). A router implant that grew into an appliance implant is worth worrying about, since most appliances run Linux under the hood.
And then there is ISE. The same September 16 bundle carried fifteen advisories for Cisco Identity Services Engine. Three of them had perfect 10.0 CVSS scores. cisco-sa-ISE-ABP-VNSW7Tn5 is CVE-2026-76460, an authentication bypass where insufficient authentication control on an API endpoint lets an unauthenticated remote attacker send a crafted request, bypass authentication entirely, and achieve command execution as root. CISA added it on September 16, the same day Cisco published, because exploitation was already underway. Unfortunately, attackers exploit vulnerabilities before advisories are published, underscoring the importance of a strong threat-hunting program.
No workarounds exist, but an infrastructure access control list restricting who can reach the appliance prevents remote exploitation. ISE is the policy engine that decides what gets onto your network, so an attacker with root access is not on your network so much as administering admission to it.
Dell’s DSA-2026-313 (CVSS 10.0) bundles 652 CVEs for Avamar, Networker Virtual Edition, the PowerProtect DP Series, and the Integrated Data Protection Appliance. Two of those 652 are on CISA’s exploited list, and one is CVE-2026-31431, the Linux kernel page-cache privilege escalation that the press called Copy Fail and is now known as the Dirty Frag exploit. The other is CVE-2025-6558 in Chromium’s ANGLE component, which has been on the KEV list since July 22, 2025, and is now shipping inside a backup appliance.
I went back through the full dataset on CVE-2026-31431, and the spread is wider than I expected. That single kernel flaw, added to KEV on May 1, 2026, now appears in 19 separate advisories across six vendors. Arista, F5, Juniper, Extreme Networks, and HPE Aruba account for one each, and Dell accounts for the other 14, spanning Enterprise SONiC, VxRail, PowerFlex, CyberSense, Data Protection Central, PowerProtect Data Manager, ThinOS 10, Metro Node, Networking OS10 twice, and this month’s backup appliances. We flagged it in July inside DSA-2026-240, again in August inside DSA-2026-299 and DSA-2026-372, and here it is again. This reflects the difficulties the supply chain creates for teams responsible for appliance security. One upstream defect created nineteen remediation tasks, each arriving on a different vendor schedule with a different advisory number.
SNWLID-2026-0016 is a perfect 10.0 covering two flaws in the SMA 1000 Series. CVE-2026-83548 is an unauthenticated server-side request forgery in the Appliance Work Place interface, and CVE-2026-83549 is an OS command injection in the Appliance Management Console rated High at 7.8. Chained, the SSRF reaches the command injection, resulting in unauthenticated remote code execution. CISA added both on September 2, and SonicWall confirms exploitation in the wild.
Compare that to the July edition, where the same appliance carrying CVE-2026-15409, an unauthenticated SSRF at 10.0, chained with CVE-2026-15410, a code injection at 7.2. Same box, same chainable one-two punch, same outcome, seven weeks apart. SonicWall’s guidance is to upgrade to the current hotfix, review the appliance for indicators of compromise, and re-image the hardware or redeploy the virtual appliance rather than clean it in place. That is the vendor telling you a patch is not the end of the job, and it’s the second time this year they have had to say that about this product line.
Check Point shipped three Critical 9.8s in this window, all unauthenticated over the network. sk1000117 is CVE-2026-85102, an authentication bypass leading to remote code execution in Remote Access and Site-to-Site VPN. SK1000118 is CVE-2026-85103, a heap overflow in ASN.1 decoding that also reaches code execution. ASN.1 decoding is the parsing layer beneath IKE and certificate handling, so that attack surface is reachable before any authentication occurs. SK1000155 is CVE-2026-91843, a stack overflow in the unauthenticated login process that gives remote code execution as root on the Security Management Server, the Multi-Domain Security Management Server, the Log Server, and the Multi-Domain Log Server. That last one is the management plane again, and it is the third vendor in this edition to ship an unauthenticated path to root on the box that administers everything else.
On September 9, Arista published advisories 0149 through 0182, thirty-four of them in a single day, which is the largest one-day batch from any vendor in this edition. Two score a perfect 10.0, and both are unauthenticated code execution on EOS. 0174 is CVE-2026-73453, where an unauthenticated P4Runtime client sends a crafted request during session initiation on TCP 9559 and takes complete administrative control of the switch. Advisory 0158 contains CVE-2026-73456, where an unauthenticated gNPSI client crafts a malicious request and gets the same outcome. Both features are off by default; Arista found both internally, and neither is known to be exploited.
Four are VeloCloud Edge and Gateway, the third month in a row that VeloCloud has appeared in this newsletter. Advisory 0179 includes the highest-scoring CVE, CVE-2026-86106, at Critical 9.6, which allows unauthenticated access to the high-availability interconnect on Edge units.
CVE-2026-86106 affects the Edge software update workflow, which accepts update bundles without properly validating their signatures because it does not restrict the digest algorithm used to verify the artifact; this is tracked as CVE-2026-86109 at Medium 6.6. An attacker who can upload packages to the Orchestrator, or who has credentials to an Edge directly, can install unauthorized software. That is a signed-update mechanism failing open, the same failure class as the Secure Boot bypass further down this newsletter, one layer up the stack. Advisory 0181 is an OS command injection in the Edge management workflow (CVE-2026-86108 at High 8.0), and 0180 is an out-of-bounds write in VCMP tunnel processing (CVE-2026-86107 at Medium 5.9)
Advisory cisco-sa-n9k-s1-rce-EH8dEtr (CVE-2026-20212, Critical at 9.8) is an unauthenticated remote code execution in the Silicon One integration on Nexus 9000 Series switches. TCP ports 43210 and 43211 are reachable in the default Layer 3 VRF. Connect, send crafted input, get code execution as root on a data-center switch. No credentials, no user interaction.
This is the kind of finding I keep coming back to in firmware and network gear, where the vulnerability is not a memory-safety bug but an interface somebody left listening because it was useful during development. Check whether those ports are reachable from anywhere they should not be, and patch.
NVIDIA’s busiest item this month is above the silicon. NVIDIA-5872 (August 25) covers NemoClaw and OpenShell across 18 CVEs, rated Critical at 9.9 through CVE-2026-65083 and CVE-2026-65093, with two unauthenticated 9.8s in CVE-2026-65081 and CVE-2026-65084. NVIDIA-5868 (September 1) covers Megatron Bridge with 30 CVEs at High, 7.8, and NVIDIA-5875 (September 8) is another Triton Inference Server bulletin at High, 7.5.
Pay close attention to NVIDIA-5809 (August 25) for Unified Fabric Manager: five CVEs at High, 8.8, adjacent-network and unauthenticated. UFM manages InfiniBand fabrics, making it the management plane for the interconnect in an AI cluster, and it falls into the same category as everything else in this edition’s “What to patch first” section. Update to version 6.24 or later. NVIDIA-5867 for DGX Spark (August 25, High at 8.2, five CVEs) rounds out the set.
On September 8, CERT/CC published VU#718077, “UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot,” credited to our own researcher Stas Lyakhov. This is in my wheelhouse, so forgive the enthusiasm, but it is also why I looked through this month’s advisories more carefully than usual.
OEMs and independent BIOS vendors routinely embed the UEFI Shell in SPI flash so service technicians can reach it, and they put controls in front of it so it does not launch during a normal boot. Stas found that an attacker who can create additional UEFI boot entries can reference the shell anyway and defeat those controls. Once the shell is running, its raw memory-access commands and its startup.nsh scripting are enough to overwrite the Secure Boot values held in memory and execute unsigned code in the preboot environment. On AMI Aptio specifically, the defect is a logic error in the BDS module’s Shell boot-option removal, so creating multiple boot entries survives the removal.
Three CVEs came out of the coordination, split by whose code is at fault. CVE-2026-20293 covers Cisco, CVE-2026-33197 covers the AMI Aptio BDS module and everything built on it, and CVE-2026-6485 covers Insyde. Four vendor advisories landed inside this window (AMI, Dell, Cisco, Lenovo). Supermicro shipped one too, a “BDS Module Bypass Secure Boot” advisory in September. Earlier in the coordination, AMI confirmed it was affected on April 9, GIGABYTE confirmed the AMI Aptio issue on July 8 and scheduled a BIOS update, and Insyde acknowledged CVE-2026-6485 on July 9 at CVSS 8.2. Intel reported it was not affected on August 7, and Phoenix Technologies on April 20.
Two things about that list are worth your attention:
I keep coming back to this class of bug because the shell is not a backdoor somebody planted. It is a legitimate diagnostic tool, deliberately embedded, signed with a trusted certificate, and capable of writing arbitrary memory. Our earlier BombShell work found the same primitive in signed shell binaries on roughly 200,000 Framework laptops and desktops. This time it is the copy sitting in your infrastructure platform’s SPI flash.
If you attest your servers with Secure Boot and measured boot and consider that question closed, this advisory reopens it. Check your firmware levels against the four advisories above, audit UEFI boot entries for additions nobody made deliberately, and remember that these fixes need OEM firmware tooling rather than your OS patch process.
Eighty-four advisories were revised during this window without being newly published. Nine vendors account for all of them: Lenovo at 43, Dell at 20, HP at 7, Cisco at 5, HPE at 4, Intel at 2, and Fortinet, Juniper, and Palo Alto at 1 each. By original publication date, 64 are from 2026, 14 from 2025, five from 2024, and one from 2021. That 2021 entry is Juniper JSA11171, a Junos OS and Junos OS Evolved bulletin for multiple NTP vulnerabilities, originally published March 30, 2021, at High, 8.8, and revised on September 4, 2026, more than five years later. The update clarified: “JSA updated to reflect that “restrict … noquery” isn’t required but a recommendation.” Five of the 84 revisions touch a CVE that is on CISA’s exploited list.
The management plane, month two. In August, I argued that attacks were landing on the systems that configure infrastructure rather than on the infrastructure itself, and this month the pattern not only held; it broadened. Cisco FMC took a KEV addition on a perfect 10.0 plus six new advisories in a day. Cisco ISE took three separate 10.0s, one of them exploited before anyone published a word about it. HPE Fabric Composer took a 10.0 across 52 CVEs. EdgeConnect SD-WAN Orchestrator took a 9.9 across 39. The Telco Network Function Virtual Orchestrator took an 8.9. NVIDIA Unified Fabric Manager took an 8.8. Dell SmartFabric Manager took a 9.2, carrying a kernel flaw that entered the KEV list during the window. SonicWall’s NSM On-Prem console took a 9.1. Arista’s VeloCloud Edge took four advisories, one of which lets an attacker who reaches the Orchestrator push unsigned software to every Edge underneath it. And ten of Arista’s thirty-four EOS advisories are in the switch’s own gRPC and OpenConfig management interfaces, including two unauthenticated paths to code execution at a perfect 10.0.
None of those is a firewall, switch, router, or fabric. Each one is the console that configures them, holds their credentials, and provides a change-control path into all of them at once. An attacker who reaches Fabric Composer doesn’t need a switch vulnerability, and an attacker with root on ISE doesn’t need to defeat your network access control because they now administer it. This is the second consecutive month the highest-value exploited flaws in infrastructure were in administrative software, so treat these platforms as high-value targets and patch, monitor, and harden them accordingly.
The Linux open-source supply chain problem did not go unnoticed. One Linux kernel privilege escalation, CVE-2026-31431, now appears in 19 advisories across six vendors, 14 of those advisories from Dell alone. Dell’s DSA-2026-313 bundles 652 CVEs and DSA-2026-343 bundles 522, and with 18 CVEs in common, they account among them for 1,156 of the 1,699 distinct CVEs in this edition, which is 68% of the total. Counting CVEs in that environment measures upstream release cadence, not your risk, and this is why we lead with advisories. The harder part is that those numbers only mean something if you know what is inside the appliance. A backup product inheriting a Chromium graphics flaw from 2025 and a switch fabric manager inheriting a kernel flaw from August are the same story told twice: the software bill of materials for the box in your rack is somebody else’s build list, and it changes without asking you.
Preboot trust is still the layer nobody patches on schedule. Our VU#718077 disclosure drew fixes from Cisco, Lenovo, Dell twice, and Supermicro, and each is a firmware update your OS patch process will not deliver. Two of those four advisories score High at 8.7, above most of what is in the CVSS-critical column of this newsletter, and none of them will show up in a scan that reads OS package versions. The AMI Aptio defect also multiplies the same way the TPM reference code did in August: one logic error in a BDS module reaches every platform built on it, which is why the CVE shows up in a Dell client BIOS advisory from May and a Lenovo BIOS roundup from September at the same time.
Severity and priority are more complicated than just exploitation. Forty-two advisories in this window are CVSS-critical, and 71 are remotely exploitable without authentication, and those are not the same vulnerabilities. Meanwhile, the flaws actually being used include a Medium at 5.3 from August’s Cisco FMC static credential, still on the KEV list, and a 7.8 SonicWall command injection whose value comes entirely from being chained to a 10.0 SSRF on the same appliance. Two of this month’s most serious exploited items, the Cisco ISE bypass and the MikroTik SSH chain, were in use before a patch or an advisory existed, which no score of any kind was going to tell you.
Start with what is reachable and what you actually run. Patch FMC to the September hardening release and re-run your Cisco incident response playbook, because exploitation has been confirmed since August. Patch ISE immediately and put an access control list in front of it, then the Secure Email Gateway, because a crafted email delivering the adversary root access is not a flaw you leave open over a weekend. Get SMA1000 and NetScaler current and hunt on them rather than assuming the patch closed the incident. Then read your revised advisories, because 84 of them changed while nobody was looking, and one of those changes was a vendor admitting that a perfect 10.0 had been under attack since August.
A monthly rundown of the security advisories that matter for the hardware running everything. Network gear, servers, chips, firmware, and BMCs. New edition every month.
Cisco Secure Firewall Management Center, then Cisco ISE, then the Cisco Secure Email Gateway. All three are confirmed exploited. Then SonicWall SMA1000 and the HPE Networking orchestrators.
Because CISA added it to the exploited list on September 9. Cisco then admitted it had known since August. The advisory is six months old, and the attacks are current.
Talos tracks three clusters, UAT-12197, UAT-11823, and UAT-11988, spanning state-sponsored and ransomware actors. The implant they drop is a Cyclops Blink variant, publicly associated with Sandworm.
No. The campaign runs OmniQuery.pl against the mdb database to pull the FMC user table and its password hashes. If that ran on your box, rotate credentials.
Because several vendor feeds we reported as stale got fixed in between. 72 of this month’s 158 advisories only arrived after our first pass. August was undercounted. Comparison resumes when ingestion is stable.
Six that change what you do. A Cisco 10.0 that became actively exploited. A Dell switch OS roll-up that gained 20 CVEs. An HP firmware advisory that gained 314 affected machines. Details are in “Revised, Not New.”
Because they are being exploited right now. MikroTik is not a vendor we track, and the Citrix advisory was published six days before this window opened. We would rather tell you that than leave the flaws out.
Our own research. CERT/CC published it as VU#718077 on September 8, credited to Stas Lyakhov: three CVEs, four vendor advisories inside this window.
It needs privileged access or physical access, so it is not a remote takeover. But exploit code is public for the Cisco variant; it defeats Secure Boot, and it reaches roughly 300 BIOS versions across UCS servers and appliances, including FMC and Nexus Dashboard.
Because the note has not been revised since it was published on September 8. Dell shipped two advisories and Lenovo one. Do not read the VINCE vendor table as the current patch state.
1,699 across 158 advisories, and 1,156 of them come from two Dell roll-ups. Count advisories, not CVEs.
It was, until we fixed it. Thirty-four Arista advisories landed in our capture with no CVSS and no CVEs because our enrichment step never ran on them. We scraped Arista’s pages, recovered 45 CVEs, and the chart and the counts here reflect that.
