Published: 09/11/26
Today’s pattern is management-plane root: when the systems that configure firewalls, terminate VPN, and run ERP kernels become the foothold. Cisco FMC is under active exploitation for OS root, Fortinet’s CAPWAP bug is dropping a FortiGate-native RAT, Check Point shipped twin CVSS 9.8s in the VPN certificate path, and SAP’s OVERPASS note is unauthenticated OS command execution on NetWeaver and Web Dispatcher.
Lead Story
Cisco FMC CVE-2026-20079 Puts Firewall Management at Root
CVE-2026-20079 is a CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center. Crafted HTTP requests to the web interface yield script execution and root on the OS. CISA added it to KEV on September 9 (due September 12). Talos is tracking three clusters—UAT-12197, UAT-11823 (tooling overlap / TTP-consistent with Sandworm), and UAT-11988 (TTP-consistent with Qilin)—using this bug and, as related ITW context, static-credential CVE-2026-20316.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
Why it matters: Patch FMC hotfixes now, pull the management interface off the Internet, and forensically triage anything that was reachable—including /var/tmp/license.tmp and Tomcat webroot drops.
Read more on CyberExperts: Read the analysis
Also Worth Your Attention
Fortinet PivotC2 After cw_acd RCE
CVE-2025-25249 (Fortinet CVSS 7.4 vs NVD/SOCRadar 9.8) is unauthenticated heap overflow in cw_acd, now dropping the PivotC2 Node.js RAT. SOCRadar-derived counts: 30,000+ IPs targeted, 178 infections. KEV since September 9.
Why it matters: Patch FortiOS / FortiSwitchManager fixed releases, lock down CAPWAP-CONTROL, and triage internet-exposed FortiGates for July–forward implant activity.
Read more on CyberExperts: Read more
Check Point Twin VPN Certificate 9.8s
CVE-2026-85102 and CVE-2026-85103 are unauthenticated RCE bugs in VPN certificate validation and ASN.1 decoding. No confirmed ITW. Fix via LivePatch Take 24 / latest Jumbo; R82.20 not affected.
Why it matters: Same-week LivePatch on R81.20 / R82 / R82.10; tighten UDP/500 and UDP/4500 if you cannot patch today.
Read more on CyberExperts: Read more
SAP OVERPASS: Unauth OS Command Exec on the Kernel
CVE-2026-44756 (Note 3747649, CVSS 10.0) corrupts Extended Passport processing for unauthenticated OS command execution on NetWeaver / Web Dispatcher 9.16. Companion same-cycle S4GET CVE-2026-58240. Onapsis’s >10,000 internet-facing figure is an estimate; no ITW claimed.
Why it matters: Ship Notes 3747649 and 3759472; inventory ICM and Web Dispatcher exposure before a public exploit arrives.
Read more on CyberExperts: Read the analysis
Go Deeper
Editorial Promise
CyberExperts should help you turn headlines into decisions. The value is in pulling the operational facts forward before the day turns them into background noise.
Start your morning with the signal that matters.
Subscribe to the 5-Minute Cyber Brief
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
Free. Weekday mornings. Unsubscribe anytime.
Built from 100+ trusted cybersecurity sources.