Cybersecurity Watch: Attackers Target Enterprise Infrastructure Management
Watch Tech Series · Cybersecurity Watch | September 24, 2026
Daily cybersecurity intelligence covering enterprise infrastructure, control-plane security, vulnerabilities, identity, networks, data, and emerging attack surfaces.
Enterprise cybersecurity is increasingly becoming a battle over the systems that control the infrastructure itself. Recent exploitation of Check Point Security Gateway and Arista VeloCloud Orchestrator vulnerabilities shows attackers targeting VPN platforms, security appliances, and network-management systems rather than only individual endpoints.
The broader pattern is concentrated risk around the enterprise control plane. Management consoles, orchestration platforms, identity systems, and infrastructure APIs can provide privileged access, network visibility, and configuration authority across multiple downstream systems. As infrastructure becomes more software-defined, centralized, and remotely managed, the platforms that control the environment are becoming high-value targets in their own right.
Editorial Position
The important cybersecurity question is shifting from “Are our devices secure?” to “Who controls the systems that control our devices?”
Lead Story
Control-Plane Security
The Management Layer Is Becoming a Prime Target
Source: InfraTrust / BleepingComputer
Modern enterprises depend on a relatively small number of systems to configure, monitor and administer large infrastructure estates. These include network-management consoles, firewall-management platforms, VPN gateways, SD-WAN orchestrators, identity systems, cloud-management interfaces, storage controllers and infrastructure APIs.
InfraTrust’s September report tracked 158 security advisories across 17 vendors and 1,699 vulnerabilities. Forty-two advisories were rated critical, eight carried a maximum CVSS score of 10.0, and 71 could be exploited remotely without authentication. Five advisories involved vulnerabilities that ultimately appeared in CISA’s Known Exploited Vulnerabilities catalog.
The structural signal is more important than the total vulnerability count. InfraTrust said that, for the second consecutive month, the most valuable exploited infrastructure flaws involved administrative software—the systems used to configure and control enterprise infrastructure.
| Management Layer | Why It Matters |
|---|---|
| Network consoles | Can expose topology, credentials, routing policies, and configuration authority across distributed infrastructure. |
| VPN gateways | Bridge external networks and internal environments, making them valuable initial-access targets. |
| SD-WAN orchestration | Centralizes control over branch, edge, and cloud-connected networks. |
| Cloud control planes | Can enable changes to identity, compute, storage, networking, and security policies through privileged APIs. |
| AI infrastructure management | Controls GPU clusters, high-speed fabrics, storage, model-serving systems, and agent runtimes. |
Structural shift: Attackers are moving from device compromise toward infrastructure control. A compromised management system can become a platform for credential theft, lateral movement, policy manipulation, and persistence across the enterprise.
Vulnerability Watch
Vulnerability Watch 01
Check Point Security Gateway Vulnerabilities Under Active Exploitation
CVE-2026-85102 · CVE-2026-93616
Check Point confirmed active exploitation of two Security Gateway vulnerabilities affecting VPN certificate handling and the Management web service. CVE-2026-85102 is a pre-authentication remote-code-execution vulnerability in VPN certificate-handling functionality. CVE-2026-93616 is a pre-authentication path-traversal flaw in the Management web service that can enable script execution and Java class loading.
Check Point said exploitation of CVE-2026-93616 began as a zero-day on July 23, while malicious activity involving affected Spark customers was observed beginning September 12. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog and gave U.S. federal civilian agencies a September 25 remediation deadline.
The vulnerabilities are especially serious because they affect systems placed directly at the boundary between external networks and internal enterprise environments. A pre-authentication flaw removes the need for an attacker to first obtain a legitimate account, while a compromised security gateway can provide network visibility, certificates, trusted connections, and privileged placement.
Check Point recommends applying the relevant LivePatch or fixed Jumbo Hotfix releases for supported Security Gateway branches. Where immediate updating is not possible, the company advises restricting VPN implied rules and limiting Site-to-Site and Remote Access VPN exposure to necessary services and known source ranges where feasible.
Security implication: Internet-facing security appliances must be treated as high-value computing platforms—not as routine network hardware.
Vulnerability Watch 02
Arista Patches Actively Exploited VeloCloud Orchestrator Zero-Day
CVE-2026-93952
Arista Networks patched CVE-2026-93952, a maximum-severity zero-day affecting on-premises VeloCloud Orchestrator deployments. VeloCloud Orchestrator is the centralized platform used to configure, monitor, and manage VeloCloud SD-WAN environments and associated edge devices. ]
The flaw involves improper input validation in deployments using certificate-based authentication from VeloCloud Edge to the orchestrator. Arista said a remote attacker could access privileged internal VCO host functionality in a low-complexity attack without prior privileges or user interaction. The attacker would need network access to the VCO web interface and access to the public portion of the VeloCloud Edge authentication certificate, but VCO tenant or operator credentials would not be required.
CISA added CVE-2026-93952 to its KEV catalog on September 23 and gave federal agencies until September 25 to secure affected systems. Arista said hosted deployments on VCO 5.2.3.16 or later and 6.4.2.8 or later were already patched, with fixes planned for older supported branches.
Arista advises administrators to restrict VCO web-interface access to administrative networks, review recent administrative activity, inspect web and nginx logs for suspicious requests, and preserve relevant logs before remediation if compromise is suspected.
Infrastructure implication: The software controlling distributed enterprise networks is itself becoming a high-value attack surface.
Infrastructure Management Under Pressure
Infrastructure Security Watch
The Important Signal Is Where Vulnerabilities Are Appearing
InfraTrust identified multiple security advisories affecting management systems across enterprise networking, security, data-center, and infrastructure vendors. Examples included Cisco Firewall Management Center, Cisco Identity Services Engine, SonicWall management infrastructure, Arista management interfaces, HPE infrastructure management, NVIDIA infrastructure management, and Dell infrastructure-management products.
These platforms are valuable because they aggregate administrative authority and infrastructure context. Their compromise can provide a better path to lateral movement than a random endpoint vulnerability, particularly when the management system has trusted access to many downstream devices.
| Platform Example | Potential Blast Radius |
|---|---|
| Cisco Firewall Management Center | Managed firewall infrastructure, policies, credentials, and network access paths. |
| Cisco Identity Services Engine | Identity, authentication, and network-access policy across enterprise environments. |
| SonicWall management systems | Security-device administration, remote access and centralized policy management. |
| NVIDIA and HPE infrastructure management | Data-center, compute, fabric and high-performance infrastructure operations. |
| Dell infrastructure-management products | Storage, networking, virtualization and data-center administration. |
What changes: Security teams should classify management platforms according to the infrastructure they can control, not merely according to the software label on the product.
Infrastructure Security Example
A Management-System Compromise Can Become a Ransomware Path
InfraTrust highlighted CVE-2026-20079, a maximum-severity Cisco Secure Firewall Management Center authentication-bypass vulnerability. The flaw enables an unauthenticated attacker to send crafted HTTP requests to the FMC web interface and execute scripts and commands as root. Cisco confirmed active exploitation, and CISA added the vulnerability to its KEV catalog.
Cisco Talos associated observed activity with threat clusters including UAT-12197, UAT-11823, and UAT-11988. Reported activity included reconnaissance with built-in tools, tunneling, credential harvesting, and, in some cases, deployment of Qilin ransomware.
The example demonstrates why management-layer vulnerabilities should not be evaluated only by asking whether the affected product stores business data. A firewall-management platform may not be the final data target, but it can provide the administrative access, network positioning, and credentials needed to reach systems that hold or process that data.
Attack path: Management-system compromise → credential access → lateral movement → policy or network manipulation → data theft, disruption, or ransomware.
The Supply-Chain Multiplier
Infrastructure Supply Chain
One Upstream Vulnerability Can Become Dozens of Enterprise Tasks
Infrastructure security teams often face a hidden multiplier: one upstream vulnerability can appear across many products, vendors, and deployment models. The result is that one CVE does not necessarily mean one patch.
InfraTrust cited CVE-2026-31431, a Linux kernel privilege-escalation vulnerability known as CopyFail, as an example. The vulnerability was added to CISA’s KEV catalog in May and later appeared in 19 separate security advisories across six vendors. Arista, F5, Juniper, Extreme Networks, and HPE issued advisories for products containing the vulnerable component, while Dell accounted for 14 advisories across products including VxRail, PowerFlex, ThinOS, PowerProtect, and Networking OS10.
| Traditional View | Infrastructure Reality |
|---|---|
| One CVE equals one product update. | One upstream flaw can affect many products and product branches. |
| Vendor advisory closes the task. | Teams must identify exposure, schedule maintenance, patch, test, and verify every affected deployment. |
| Product inventory is sufficient. | Dependency and component visibility are required to understand the true attack surface. |
Operational lesson: Vulnerability management must connect software composition, infrastructure inventory, vendor advisories, maintenance windows, and post-remediation verification.
Cybersecurity Meets AI Infrastructure
AI Infrastructure Security
The AI Control Plane Is Becoming a Security Priority
Enterprises are deploying AI clusters, GPUs, high-speed networking, distributed storage, cloud infrastructure, sovereign AI environments, edge systems, and autonomous agents. Each layer introduces management interfaces, APIs, credentials, orchestration tools, and privileged automation paths.
Protecting an AI deployment therefore requires more than securing the model or application. Security teams must also protect the infrastructure that schedules accelerators, manages network fabrics, provisions storage, distributes models, and governs agent permissions.
| AI Infrastructure Layer | Security Concern |
|---|---|
| GPU and accelerator management | Unauthorized scheduling, disruption, data exposure, and resource theft. |
| High-speed fabric control | Network visibility, traffic manipulation, and cluster-wide availability risk. |
| Model-serving systems | Model substitution, unauthorized inference, data leakage, and service disruption. |
| Agent runtimes | Excessive permissions, unsafe tool calls, credential misuse, and untraceable autonomous actions. |
| Cloud control planes | Cross-account access, infrastructure modification, identity compromise and persistence. |
Strategic question: Can enterprises secure the control plane of AI infrastructure as aggressively as they secure the AI workloads themselves?
Identity and Data Extortion Watch
Public-Sector Security
FBI Investigates Alleged ShinyHunters Breach of Jobs Platform
Source: The Record from Recorded Future News
The FBI is investigating claims of unauthorized activity affecting FBIjobs.gov after the ShinyHunters cybercriminal group defaced the job-application website and claimed to have taken information involving current and former employees and applicants. The FBI confirmed that it was investigating the claims but did not confirm the full scope of any data compromise.
ShinyHunters provided samples of 5,000 purported FBI agent records to 404 Media and other outlets. Recorded Future News reported that the samples were confirmed as legitimate, although the scope, source, completeness, and operational impact of the alleged dataset remained under investigation.
The incident illustrates why recruitment and identity platforms remain valuable targets. Such systems may hold sensitive contact information, employment records, application data, and background-related information. Public-sector data can also create risks beyond ordinary identity theft, including targeted social engineering, harassment, and physical-security concerns.
Attribution note: Website defacement, confirmed investigation, and verified data samples should be reported separately from an independently confirmed full-scale breach.
What Security Teams Should Watch
| 1. Management interfaces | Treat administrative consoles, orchestration platforms, and device-management systems as critical infrastructure. |
| 2. Internet exposure | Eliminate direct public access to management systems unless unavoidable. Place remaining access behind segmentation, strong identity controls, and allowlists. |
| 3. VPN and remote access | Prioritize actively exploited vulnerabilities in security gateways, VPNs, and remote-access platforms. |
| 4. SD-WAN orchestration | Review which centralized platforms can configure distributed network devices and what credentials they hold. |
| 5. KEV vulnerabilities | Prioritize vulnerabilities with confirmed exploitation above generic severity scores in remediation queues. |
| 6. Supply-chain dependencies | Track vulnerabilities across embedded operating-system, kernel, firmware, and open-source components. |
| 7. AI infrastructure control planes | Extend security monitoring beyond AI applications to the systems managing compute, networking, storage, model serving, and agents. |
The CODEW Cybersecurity Intelligence Framework
Cybersecurity Watch evaluates enterprise risk through six connected layers:
| Layer | Security Question |
|---|---|
| Identity | Who can access the environment and with what level of privilege? |
| Endpoint | Which devices, servers, and workloads can be compromised? |
| Network | How can an attacker move through or manipulate connectivity? |
| Infrastructure | Which compute, storage, cloud, and data-center systems run the business? |
| Control Plane | Which systems configure, monitor, and change the infrastructure? |
| Data | What information can be stolen, altered, encrypted, or extorted? |
September 24 emphasis: The control plane connects identity, infrastructure, network access, and data. A weakness there can amplify the impact of vulnerabilities across every layer beneath it.
What to Watch Next
| 1. CISA KEV additions | Monitor newly cataloged vulnerabilities affecting VPNs, security appliances, network-management systems, and infrastructure control planes. |
| 2. Remote-access exploitation | Watch for continued exploitation of VPN, firewall, and remote-access platforms exposed to the public internet. |
| 3. Network orchestration | Track vulnerabilities in SD-WAN, network-fabric, identity, and centralized device-management systems. |
| 4. Infrastructure supply chain | Assess how upstream Linux, kernel, firmware, and open-source vulnerabilities propagate through enterprise products. |
| 5. AI infrastructure security | Monitor the security of GPU orchestration, high-speed networking, storage, model-serving systems, and AI-agent runtimes. |
Related CODEW Coverage
→ Cloud Computing Watch — AI Pushes Cloud Infrastructure Toward Sovereignty, Edge and Agentic Workloads
→ AI Infrastructure Watch — Securing the Infrastructure Behind Enterprise AI
→ Networking Watch — SD-WAN, Network Orchestration and the Distributed Enterprise
→ Infrastructure Software Watch — Management Platforms Become Critical Infrastructure
→ Cybersecurity Intelligence — Known Exploited Vulnerabilities and Enterprise Response
→ Semiconductor Watch — Security Risks in AI Compute and Networking Infrastructure
The Cybersecurity Watch Takeaway
The cybersecurity story this week is bigger than any individual CVE. Enterprise infrastructure is becoming increasingly software-defined, centralized, and remotely managed. That creates efficiency and scale—but it also concentrates security risk around the systems that control the infrastructure.
For security teams, the control plane must be treated as a primary security boundary. Attackers are increasingly interested not only in what an enterprise owns, but in the systems that control what the enterprise owns.
Editorial Note
The Newsroom reports what happened. Cybersecurity Watch identifies the structural implications for enterprise security architecture, infrastructure risk, and defensive priorities. Cybersecurity Watch is The CODEW's dedicated threat-and-defense intelligence series, tracking cybercrime groups, zero-days, AI security, software supply chains, vulnerability management, and enterprise security through a consistent threat → vulnerability → attack surface → exploitation → defense → business impact framework.
Vulnerability information is based on vendor disclosures, CISA catalog information, and reporting from BleepingComputer, InfraTrust, and The Record from Recorded Future News. Security teams should verify affected versions, mitigations, exploitation status, and remediation requirements directly with vendors and relevant government advisories. Educational content only. Not legal, compliance, or incident-response advice. Product coverage, data sources, and methodologies can change as the intelligence platform evolves.
Reviewed by Erwin Castro
on
Thursday, September 24, 2026
Rating:
