Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)

Eclypsium InfraTrust Report (TL-2026-2630), also tracked as InfraTrust Pulse September 2026, is a critical-severity software vulnerability scored CVSS 10, first published 2026-09-23. It is attributed to Sandworm FMC intrusion cluster (Russia) with medium confidence, affects Cisco Secure Firewall Management Center (FMC), references 15 CVEs (CVE-2026-20079, CVE-2026-20316, CVE-2026-76460), maps to 19 MITRE ATT&CK techniques (T1003, T1021.006, T1037.004), and is covered by 9 detection rules and 17 indicators of compromise.

Key facts for TL-2026-2630

Threat ID
TL-2026-2630
Also known as
InfraTrust Pulse September 2026, Copy Fail, Cisco FMC Cyclops Blink/Qilin Campaign
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-23
Last reviewed
2026-09-23
Attribution
Sandworm FMC intrusion cluster
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, technology, telecoms, finance
Target regions
Global, North America, Europe
Detection rules
9
Indicators of compromise
17

Malware and tooling in Eclypsium InfraTrust Report

Malware and tooling: AgendaCrypt, Cyclops Blink, Impacket - S0357, Invoke-TheHash

Eclypsium's September 2026 InfraTrust Pulse report documents 158 new security advisories across 17 vendors (1,699 vulnerabilities tracked, 42 critical, 8 with maximum CVSS 10.0 scores, 71 remotely exploitable without authentication, 5 added to CISA KEV) targeting enterprise network and infrastructure management systems. Cisco Talos confirmed active exploitation of a maximum-severity Cisco Secure Firewall Management Center authentication bypass (CVE-2026-20079, chained with CVE-2026-20316) by three threat clusters deploying a Cyclops Blink implant variant tied to the Sandworm/IRON VIKING group and Qilin ransomware, while a CVSS 10.0 Cisco ISE authentication bypass (CVE-2026-76460) and chained SonicWall SMA 1000 SSRF/command-injection flaws (CVE-2026-83548/83549) were also confirmed under active attack.

How Eclypsium InfraTrust Report works

Eclypsium's InfraTrust Pulse report for the August 25-September 17, 2026 window catalogs 158 new advisories across 17 network and infrastructure vendors, noting that for the second consecutive month the highest-value exploited flaws were found in administrative/management software rather than the network devices themselves.

The most severe confirmed-active campaign centers on Cisco Secure Firewall Management Center (FMC). CVE-2026-20079 (CVSS 10.0, CWE-288) is an authentication-bypass-using-an-alternate-path flaw in the FMC web interface stemming from an improper system process created at boot time; unauthenticated attackers can send crafted HTTP requests to bypass authentication and execute script files as root. Cisco disclosed it July 29, 2026 with indicators already showing exploitation; Cisco confirmed active exploitation and CISA added it to KEV on September 9, 2026. CVE-2026-20316 (CVSS 5.3) allows remote login with a low-privileged/static account and is chained with CVE-2026-20079 for privilege escalation and sensitive-data access. Cisco Talos attributed post-compromise activity on compromised FMC instances to three distinct clusters: UAT-12197 (credential-harvesting operation that deployed a JSP web shell in the Tomcat webroot and a malicious command-execution JAR that invoked FMC's built-in OmniQuery.pl utility to dump the users table, including auth_data); UAT-11823 (state-sponsored, Sandworm/IRON VIKING-linked, which trojanized the FMC package_info.pl utility via a malicious license.tmp Makeself package, established a Netcat reverse shell to attacker infrastructure, and ultimately deployed a Cyclops Blink ELF implant named "timezone_check" -- the same malware family the UK NCSC first analyzed in 2022 -- with persistence via /etc/init.d/, DNS-over-HTTPS C2 resolution, file transfer, credential harvesting, command execution, network scanning and packet-sniffing capabilities); and UAT-11988 (a Qilin ransomware affiliate that logged in via CVE-2026-20316's static credentials, abused the same package_info.pl/license.tmp mechanism, then used built-in FMC tooling and living-off-the-land techniques -- Impacket, Invoke-TheHash, a Python SOCKS5 proxy and reverse-SSH tunnels forwarding LDAP/LDAPS/Kerberos/SMB/NETBIOS/WinRM ports -- to enumerate Active Directory, harvest domain and MySQL credentials, terminate security tooling, and deploy Qilin ransomware).

A second maximum-severity flaw, CVE-2026-76460 (CVSS 10.0, CWE-648), affects Cisco Identity Services Engine (ISE) and ISE-PIC: an API endpoint that should have required authentication did not, letting an unauthenticated remote attacker bypass the web management interface and obtain root command execution. It was already under active exploitation when Cisco disclosed it September 16, 2026, and CISA added it to KEV the same day with a compressed three-day FCEB remediation deadline (September 19).

SonicWall SMA 1000 appliances (models 6210/7210/8200v) were hit by a chained zero-day pair: CVE-2026-83548 (CVSS 10.0, CWE-918/CWE-441), a pre-authentication SSRF in the Appliance Work Place that lets the appliance be abused as an unintended forward proxy, chained with CVE-2026-83549, an OS command injection in the Appliance Management Console requiring admin access. SonicWall confirmed exploitation of both in the same investigated incident and recommended re-imaging rather than in-place remediation; both were added to CISA KEV September 2, 2026.

Check Point disclosed (not yet observed exploited, but flagged "imminent" by the Dutch NCSC) CVE-2026-85102 (CVSS 9.8, VPN certificate-validation authentication bypass enabling pre-auth RCE on Security Gateway during Remote Access/Site-to-Site VPN negotiation), CVE-2026-85103 (CVSS 9.8, heap-based buffer overflow while decoding a VPN certificate's ASN.1 structure), and CVE-2026-91843 (unauthenticated login-process flaw yielding root code execution on Check Point management/logging servers). Fixes shipped via LivePatch Take 24 beginning September 9, 2026.

Arista published 34 advisories September 9, 2026 including CVE-2026-73453 (CVSS 10.0, unauthenticated arbitrary code execution via the P4Runtime service on TCP/9559, disabled by default) and CVE-2026-73456 (CVSS 10.0, unauthenticated code injection via the gRPC Network Packet Sampling Interface, gNPSI, also disabled by default); neither is known to be exploited. Cisco Nexus 9000 switches with Silicon One ASICs carry CVE-2026-20212 (CVSS 9.8), an unauthenticated root-RCE exposure discovered by Cisco TAC where TCP ports 43210/43211 are reachable via the default L3 VRF and can crash the S1HAL process or execute attacker input as root; no known public exploitation as of the September 2, 2026 advisory.

A Linux kernel local-privilege-escalation flaw, CVE-2026-31431 ("Copy Fail", CVSS 7.8), was disclosed April 29, 2026 in the algif_aead AF_ALG crypto socket interface: an in-place memory-reuse optimization added in 2017 lets an unprivileged local user corrupt the page cache backing setuid binaries and obtain root in seconds, enabling container breakout and multi-tenant compromise. It affects virtually every Linux distribution shipped since 2017 and was added to CISA KEV in May 2026; it reappeared across 19 separate vendor advisories from Arista, F5, Juniper, Extreme Networks, HPE Aruba and Dell (14 Dell advisories spanning VxRail, PowerFlex, ThinOS, PowerProtect and Networking OS10) in this reporting window, illustrating the multi-vendor supply-chain blast radius of unpatched upstream kernel code.

A family of UEFI Secure Boot bypass flaws -- CVE-2026-20293 (Cisco UCS, CVSS 7.1), CVE-2026-33197 (AMI Aptio V BDS module, CVSS 8.7) and CVE-2026-6485 (Insyde InsydeH2O, CVSS 8.2) -- share a common root cause: a UEFI Shell module embedded in SPI flash whose boot-option removal logic can be abused (via shell commands, startup scripts, or crafted boot entries) to bypass Secure Boot validation and execute unsigned pre-OS code, affecting AMI, Dell, Cisco, Lenovo and Supermicro firmware.

MITRE ATT&CK techniques used in TL-2026-2630

Credential Access

T1003 OS Credential Dumping; T1552.001 Credentials In Files

Lateral Movement

T1021.006 Windows Remote Management

Persistence

T1037.004 RC Scripts; T1505.003 Web Shell; T1542 Pre-OS Boot

Discovery

T1040 Network Sniffing; T1046 Network Service Discovery; T1087 Account Discovery

Execution

T1059.004 Unix Shell

Command and Control

T1071.004 DNS; T1090 Proxy; T1572 Protocol Tunneling

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Impact

T1489 Service Stop

defense-impairment

T1553.006 Code Signing Policy Modification

Reconnaissance

T1595.002 Vulnerability Scanning

Privilege Escalation

T1611 Escape to Host

Affected products and versions in Eclypsium InfraTrust Report

  • Cisco — Secure Firewall Management Center (FMC)
    Vulnerable versions: 7.0.0-7.7.12; 10.0.0; 10.0.1
    Fixed in: Cisco-published hotfixes for CVE-2026-20079/CVE-2026-20316
  • Cisco — Identity Services Engine (ISE) / ISE-PIC
    Vulnerable versions: 3.1.0-3.5.0 (all patch levels p1-p11)
    Fixed in: Cisco ISE emergency patch for CVE-2026-76460
  • SonicWall — SMA 1000 (SMA6210, SMA7210, SMA8200v)
    Vulnerable versions: <12.4.3-03526; 12.5.0 <12.5.0-02952
    Fixed in: 12.4.3-03526+; 12.5.0-02952+ (vendor recommends re-imaging)
  • Check Point — Security Gateway / Security Management Server / Spark Firewall
    Vulnerable versions: pre-LivePatch Take 24 builds
    Fixed in: LivePatch Take 24; Jumbo Hotfix Accumulator
  • Arista — EOS (P4Runtime, gNPSI services)
    Vulnerable versions: EOS releases with P4Runtime/gNPSI enabled pre-patch
    Fixed in: Arista September 9, 2026 fixed releases
  • Cisco — Nexus 9000 (Silicon One ASIC platforms)
    Vulnerable versions: Pre-September 2026 NX-OS releases
    Fixed in: Fixed NX-OS release; Live Protect interim shield
  • Multiple (Linux kernel upstream) — Linux kernel (algif_aead / AF_ALG)
    Vulnerable versions: Kernels released 2017-present prior to patch
    Fixed in: Patched kernel builds per distro/OEM (Ubuntu, RHEL, SUSE, Amazon Linux, Arista, F5, Juniper, Extreme Networks, HPE Aruba, Dell)
  • AMI / Insyde / Cisco — UEFI firmware (Aptio V BDS module, InsydeH2O, Cisco UCS)
    Vulnerable versions: Affected Aptio V, InsydeH2O and Cisco UCS firmware builds pre-patch
    Fixed in: Vendor-issued UEFI firmware updates for CVE-2026-33197, CVE-2026-6485, CVE-2026-20293

Remediation for Eclypsium InfraTrust Report

Patches

  • Cisco FMC hotfixes for CVE-2026-20079, CVE-2026-20316 and the September 16 sftunnel-related disclosures
  • Cisco ISE/ISE-PIC emergency patch for CVE-2026-76460
  • SonicWall SMA 1000 platform hotfix releases 12.4.3-03526 / 12.5.0-02952 or later for CVE-2026-83548/CVE-2026-83549
  • Check Point LivePatch Take 24 / Jumbo Hotfix Accumulator for CVE-2026-85102, CVE-2026-85103, CVE-2026-91843
  • Arista EOS fixed releases for CVE-2026-73453/CVE-2026-73456
  • Cisco NX-OS fixed release or Live Protect shield for CVE-2026-20212
  • Linux kernel updates addressing CVE-2026-31431 (Copy Fail) across all affected distributions and OEM platforms (Arista, F5, Juniper, Extreme Networks, HPE Aruba, Dell)
  • AMI, Insyde and Cisco UEFI firmware updates for CVE-2026-33197, CVE-2026-6485, CVE-2026-20293

Immediate actions

  • Apply Cisco FMC hotfixes for CVE-2026-20079/CVE-2026-20316 and inspect appliances for the timezone_check implant, anomalous SysV/init.d services, and a modified /var/tmp/license.tmp
  • Apply the Cisco ISE emergency patch for CVE-2026-76460; no workaround exists short of strict ACL-based network isolation of the management interface
  • Re-image (not just patch) SonicWall SMA 1000 appliances per vendor guidance for CVE-2026-83548/CVE-2026-83549 given confirmed exploitation
  • Review outbound TLS sessions on ports 43856 and 49172 and DNS-over-HTTPS traffic from FMC appliances for Cyclops Blink C2 activity
  • Block known C2/attacker IPs 89.34.96.56, 208.123.119.215, 91.214.78.118, 43.204.2.142 and scanner IP 104.218.165.253 at the perimeter

Workarounds

  • Disable P4Runtime (TCP/9559) and gNPSI services on Arista EOS if not required (disabled by default; verify no exposure)
  • Restrict access to Cisco Nexus 9000 debug ports 43210/43211 via VRF/ACL segmentation pending patching
  • Restrict FMC/ISE/SMA management interfaces to trusted administrative networks only

Longer-term hardening

  • Segment and restrict network-management-plane access (FMC, ISE, SMA, EOS, Nexus admin interfaces) behind dedicated management VLANs/ACLs, never Internet-facing
  • Deploy firmware/UEFI integrity monitoring to detect Secure Boot bypass attempts (CVE-2026-20293/CVE-2026-33197/CVE-2026-6485 class issues)
  • Establish a kernel/OS patch cadence for CVE-2026-31431 (Copy Fail) across all Linux-based network appliances and virtualization hosts
  • Deploy EDR/behavioral detection on network-management servers capable of detecting living-off-the-land tooling (Impacket, Invoke-TheHash, SOCKS proxies, reverse-SSH tunnels)

CVEs associated with Eclypsium InfraTrust Report

Weaknesses (CWE) in Eclypsium InfraTrust Report

CWE-288, CWE-648, CWE-918, CWE-441

Timeline of Eclypsium InfraTrust Report

  • CVE-2026-31431 ("Copy Fail") Linux kernel local privilege escalation publicly disclosed with proof-of-concept exploit code.
  • CVE-2026-31431 added to CISA's Known Exploited Vulnerabilities catalog.
  • Cisco publishes advisory for CVE-2026-20079 with compromise indicators; exploitation already occurring in the wild.
  • Sophos CTU researchers analyze the "timezone_check" Linux implant recovered from compromised Cisco FMC devices, identifying it as a Cyclops Blink variant likely linked to Sandworm/IRON VIKING.
  • CVE-2026-83548 and CVE-2026-83549 (SonicWall SMA 1000 SSRF/OS command injection chain) added to CISA KEV following confirmed exploitation; Cisco publishes CVE-2026-20212 (Nexus 9000) advisory the same day.
  • Cisco confirms active exploitation of CVE-2026-20079; CVE-2026-20079 added to CISA KEV; Arista publishes 34 advisories including CVE-2026-73453 and CVE-2026-73456; Check Point begins LivePatch Take 24 rollout for CVE-2026-85102/85103.
  • Cisco Talos publishes detailed technical analysis attributing FMC post-compromise activity to three clusters (UAT-12197, UAT-11823, UAT-11988), documenting the Qilin ransomware deployment chain and IOCs.
  • Cisco discloses CVE-2026-76460 (ISE authentication bypass, CVSS 10.0), already under active exploitation at disclosure; additional FMC sftunnel-related vulnerabilities also disclosed; CVE-2026-76460 added to CISA KEV same day.
  • CISA BOD 26-04 remediation deadline for FCEB agencies to patch CVE-2026-76460.
  • Eclypsium publishes the September 2026 InfraTrust Pulse report aggregating the reporting period's 158 advisories across 17 vendors and highlighting the confirmed active-exploitation campaigns.

Sources cited for Eclypsium InfraTrust Report

More in vulnerability

Detection coverage for TL-2026-2630

As of 2026-09-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2630 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats