Cisco confirms active exploitation against the firewall management planeBlueMoon turns the browser patch gap into a shared espionage capabilityEU product-security reporting clocks start tomorrowSpringfield keeps schools closed as cyber disruption reaches…
Cisco confirms active exploitation against the firewall management plane
Cisco has now confirmed active exploitation of a maximum-severity authentication bypass that can provide unauthenticated attackers with root access to Secure Firewall Management Center.
Security.io Intelligence Desk · Thursday, 10 September 2026
Executive consequence
Cisco’s September revision confirms that CVE-2026-20079 is being exploited. Crafted HTTP requests can bypass authentication and execute scripts or commands as root on affected Secure FMC systems. Cisco provides a specific log check and release-specific hot fixes, but no workaround.
Decision today
Inventory every on-premises Cisco Secure FMC instance, release branch and management-interface exposure.
Proofpoint’s September 9 research documents rapid adoption of BlueMoon by four espionage-focused threat clusters. The kit combines CVE-2026-85046, an unnumbered V8 sandbox escape and CVE-2026-85880 on specified older Windows builds.
Do today
Inventory browser versions and Windows build combinations across targeted user groups.
Cyber Resilience Act Article 14 reporting applies from September 11, 2026. Manufacturers must provide a 24-hour early warning and a 72-hour notification for actively exploited vulnerabilities or severe incidents affecting products with digital elements. Final-report timing differs between the two.
Do today
Name the accountable CRA reporting officer and deputies.
Springfield extended school closures through September 11 after a districtwide Level 4 severe cyber incident disrupted essential systems. Officials said an outside group gained network access and blocked online programmes, including access to vital student medical records.
Do today
Restore read-only access to student medical records before reopening.
Veradigm’s SEC filing states that an unauthorised party obtained credentials from a third-party vendor environment and used them to download patient personal data through a limited Veradigm API.
Do today
Ask Veradigm whether your organisation or patients are affected.