Eclypsium: attackers shift focus to infrastructure management systems
Eclypsium's September InfraTrust Pulse report tracked 158 advisories from 17 vendors covering 1,699 vulnerabilities between August 25 and September 17, including 42 critical flaws, eight with a maximum CVSS score of 10.0 and 71 remotely exploitable without authentication. For a second month, the most dangerous exploited flaws hit administrative consoles such as Cisco FMC, Cisco ISE, SonicWall SMA 1000 and Check Point.
- 158 advisories, 1,699 vulnerabilities, 42 critical and eight scoring CVSS 10.0
- 71 flaws can be exploited remotely without authentication
- CVE-2026-20079 in Cisco FMC allows unauthenticated root access, attacks confirmed
- SonicWall SMA 1000 flaws chained for unauthenticated remote code execution
Read next
Security