NewsTradingSentimentEventsCommunityBriefing
Tech

Cisco Management Flaws Exploited by State Actors and Ransomware

By Tech Desk · · 1 min read
A flat-vector illustration of a network equipment rack with blinking status lights

Attackers are targeting the control centers of enterprise networks, exploiting critical flaws in Cisco systems to gain full device control.

Key points

  • InfraTrust tracked 1,699 vulnerabilities across 17 vendors between August 25 and September 17, with 42 rated critical.
  • Cisco confirmed active exploitation of CVE-2026-20079, an authentication bypass in its Firewall Management Center, on September 9.
  • Sophos identified the timezone_check implant as a variant of Cyclops Blink, malware linked to the Sandworm group.

Attackers are increasingly targeting the management systems used to control enterprise infrastructure. This trend was highlighted in the September edition of Eclypsium's InfraTrust Pulse report. The data covers a period from August 25 to September 17.

During this window, researchers tracked 158 new security advisories across 17 vendors. These advisories covered 1,699 vulnerabilities. BleepingComputer notes that many of these flaws are in administrative software. Attackers now view these platforms as high-value targets for compromise.

Critical flaws in Cisco systems

One severe issue is CVE-2026-20079 in Cisco Secure Firewall Management Center. This flaw allows unauthenticated attackers to send crafted requests to the web interface. They can then execute scripts and commands as root on vulnerable devices.

Cisco confirmed on September 9 that this vulnerability was being actively exploited. The company stated its team became aware of the attacks in August. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day.

State actors and ransomware involvement

Cisco Talos linked the activity to three threat clusters. These include state-sponsored actors and ransomware gangs. Attackers used built-in tools for reconnaissance and deployed tunneling utilities.

Sophos analyzed a Linux implant named timezone_check found on compromised devices. It is a variant of Cyclops Blink malware. This malware has been previously associated with the Sandworm threat group.

Additional vulnerabilities in identity services

Cisco also disclosed multiple critical vulnerabilities in its Identity Services Engine platform. Three of these flaws received a maximum CVSS score of 10.0. One specific flaw, CVE-2026-76460, allows remote command execution as root.

CISA added this flaw to the KEV catalog on September 16. Cisco stated there are no direct workarounds available. However, restricting access using infrastructure access control lists can prevent remote exploitation.

Based on reporting by BleepingComputer, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories