Today’s lead:Cisco confirms active exploitation against the firewall management planeBlueMoon turns the browser patch gap into a shared espionage capabilityEU product-security reporting clocks start tomorrowSpringfield keeps schools closed as cyber disruption reaches…
Front page · Daily intelligence
Cisco confirms active exploitation against the firewall management plane
Cisco has now confirmed active exploitation of a maximum-severity authentication bypass that can provide unauthenticated attackers with root access to Secure Firewall Management Center.
By Security.io Intelligence Desk · Executive analysis
Cisco’s September revision confirms that CVE-2026-20079 is being exploited. Crafted HTTP requests can bypass authentication and execute scripts or commands as root on affected Secure FMC systems. Cisco provides a specific log check and release-specific hot fixes, but no workaround.
Why today: Cisco’s March disclosure moved above the other selected developments because the September 9 confirmation of active exploitation changes both the decision and the closure standard for a privileged firewall control plane. The new fact is not the vulnerability…
“Inventory every on-premises Cisco Secure FMC instance, release branch and management-interface exposure.”
Decision owner: Network security leadership, with incident response, infrastructure operations and vulnerability management.
Decision horizon: Immediate: hunt and contain before accepting patch deployment as closure.
Cisco’s September revision confirms that CVE-2026-20079 is being exploited. Crafted HTTP requests can bypass authentication and execute scripts or commands as root on affected Secure FMC…
Today’s action: Inventory every on-premises Cisco Secure FMC instance, release branch and management-interface exposure.
Proofpoint’s September 9 research documents rapid adoption of BlueMoon by four espionage-focused threat clusters. The kit combines CVE-2026-85046, an unnumbered V8 sandbox escape and CVE-2026-85880 on…
Today’s action: Inventory browser versions and Windows build combinations across targeted user groups.
Cyber Resilience Act Article 14 reporting applies from September 11, 2026. Manufacturers must provide a 24-hour early warning and a 72-hour notification for actively exploited vulnerabilities…
Today’s action: Name the accountable CRA reporting officer and deputies.
Springfield extended school closures through September 11 after a districtwide Level 4 severe cyber incident disrupted essential systems. Officials said an outside group gained network access…
Today’s action: Restore read-only access to student medical records before reopening.
Veradigm’s SEC filing states that an unauthorised party obtained credentials from a third-party vendor environment and used them to download patient personal data through a limited…
Today’s action: Ask Veradigm whether your organisation or patients are affected.
Signal desk
Interactive editorial evidence
Lead decision score
Cisco Secure FMC enterprise decision score
Hover or tap a bar for its exact value and the editorial meaning behind it. Keyboard: focus the chart and use ↑ or ↓.
Scores are editorial, not source metrics: 0–100 based on verified exploitation, privileged control-plane placement and recovery consequence.
Hover or tap a point to see the story title, new references, cumulative evidence, source mix and why the story entered today’s edition. Keyboard: use ← or →.
This line shows cumulative cited references across the lead and four supporting briefs.