
Cyberattackers are increasingly targeting the management systems that control enterprise infrastructure, creating opportunities to compromise entire environments rather than individual devices.
The September edition of Eclypsium‘s InfraTrust Pulse tracked 158 new security advisories across 17 vendors, covering 1,699 distinct CVEs between August 25 and September 17. Forty-two advisories were rated Critical, eight received a perfect CVSS score of 10.0 and 71 were remotely exploitable without authentication.
Some of the most serious vulnerabilities affected the platforms responsible for administering other infrastructure. Cisco’s Firewall Management Center (FMC), for example, was affected by CVE-2026-20079, a CVSS 10.0 vulnerability that can give an unauthenticated attacker root access to the underlying operating system. Cisco has confirmed the vulnerability was actively exploited.
Cisco Identity Services Engine (ISE) was also affected by three vulnerabilities carrying perfect 10.0 scores. One, CVE-2026-76460, allows an unauthenticated remote attacker to bypass authentication and execute commands as root. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog the same day Cisco published its advisory because exploitation was already underway.
The pattern extends beyond Cisco. The report identified serious vulnerabilities affecting HPE Fabric Composer, NVIDIA Unified Fabric Manager, Dell SmartFabric Manager and management interfaces within Arista products, among others. These systems can hold credentials and provide centralized paths for configuring large portions of an organization’s infrastructure.
Infrastructure security also extends beneath the operating system. September brought vendor fixes for a UEFI Shell Secure Boot bypass discovered by Eclypsium researcher Stas Lyakhov. The vulnerability can enable an attacker with the ability to create additional UEFI boot entries to access an embedded UEFI Shell, manipulate Secure Boot values in memory and execute unsigned code in the preboot environment.
The findings suggest security teams need to treat infrastructure management platforms as high-value assets in their own right. That means restricting access, monitoring them for suspicious activity and prioritizing remediation based not only on vulnerability scores, but also on reachability, exploitation and the level of control a compromised system could provide.
Join our LinkedIn group Information Security Community!









