TODAY
Cisco firewall auth bypass and three near-certain exploits demand immediate patching.
THE THREE
- KEV#1 · CVE-2026-20079
Cisco
What: If your organization uses Cisco Firewall Management Center or Security Cloud Control, an attacker on the internet can bypass your login entirely — no credentials needed — and take control of your firewall management plane, exposing your entire network. This is actively exploited with a 76% exploit probability and a perfect CVSS 10.
Why it moved: Actively exploited · Widely deployed · Critical severity · 76% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply Cisco's patch for FMC and SCC immediately, prioritize over other work.
- KEV#2 · CVE-2026-33824
Microsoft
What: A flaw in Windows' IKE (VPN/IPsec) service lets a remote attacker run their own code on your Windows machines without being logged in — a ransomware or takeover scenario affecting virtually every Windows environment. Actively exploited with 73% exploit odds.
Why it moved: Actively exploited · Everyone runs this · Critical severity · 73% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Deploy the Microsoft patch for the IKE service on all Windows systems now.
- KEV#3 · CVE-2026-8037
Progress
What: Progress LoadMaster (a popular load balancer) has a command injection flaw that attackers are exploiting at near-certainty — EPSS sits at 99.6% — letting anyone on the internet run commands on your appliance with no login required. Full network compromise is the likely outcome.
Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch or isolate every Progress LoadMaster appliance from public internet access immediately.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 11M
- Relationships
- 67M
- Threat actors
- 281
- Indicators
- 650k
- Feeds live
- 19
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.