Cisco released emergency fixes for two critical (CVSS 10.0) vulnerabilities in its firewall management software that could allow remote, unauthenticated attackers to execute code and gain root-level access to the underlying operating system. The issues are tracked as CVE-2026-20079 and CVE-2026-20131, and reporting emphasized the risk profile given Cisco’s widespread deployment in large enterprises and the historical interest of sophisticated actors in rapidly weaponizing Cisco bugs.
Available reporting stated there were no confirmed in-the-wild exploitation reports at the time of publication, but urged rapid patching due to the combination of unauthenticated reachability and full compromise potential. Separate coverage packaged the Cisco flaws alongside other weekly security items (e.g., Tycoon2FA infrastructure takedown and other incidents), but the Cisco item consistently described the same two maximum-severity firewall management vulnerabilities and their impact (RCE leading to root access).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
A U.S. sentencing was handed down in a case involving trafficking in Microsoft Certificates of Authenticity or license labels. The case reflected continued law-enforcement action against software-related fraud.
The University of Mississippi Medical Center restored operations after a ransomware incident disrupted clinical and IT systems for nine days. The recovery marked a significant operational milestone following the attack.
Researchers reported that the China-linked Silver Dragon activity cluster targeted government organizations using Cobalt Strike and custom tooling overlapping with the APT41 ecosystem. The reporting expanded attribution and technical understanding of the campaign.
Attackers distributed a fake RedAlert rocket-warning Android app through SMS phishing messages impersonating Israel's Home Front Command. The app deployed multi-stage spyware with extensive permissions and banking-trojan-like capabilities.
LexisNexis confirmed a security breach after FulcrumSec leaked data it claimed to have stolen from the company's AWS environment. The claims referenced an alleged React2Shell-based compromise.
An international operation led by agencies including the FBI and Europol dismantled the LeakBase breach forum. Authorities seized infrastructure and made arrests as part of the takedown.
Microsoft and law enforcement disrupted the Tycoon 2FA phishing-as-a-service platform by seizing domains and related infrastructure. The action targeted a service used to facilitate large-scale phishing and credential theft.
Cisco released emergency fixes for two CVSS 10.0 remote, unauthenticated RCE vulnerabilities in its firewall management software. The flaws were described as critical and required immediate remediation.
Cisco disclosed that previously patched vulnerabilities affecting Catalyst SD-WAN Manager were being actively exploited in the wild. The warning elevated concern beyond the original patch release.
CISA added the VMware Aria Operations command-injection vulnerability to its Known Exploited Vulnerabilities catalog, signaling active exploitation risk and increasing urgency for patching.
Broadcom released a patch for a command-injection vulnerability in VMware Aria Operations. The flaw was later noted as significant enough to be added to CISA's Known Exploited Vulnerabilities catalog.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.