TODAY
Cisco Firewall, Progress LoadMaster, and Apache Tomcat Under Active Attack
THE THREE
- KEV#1 · CVE-2026-20079
Cisco
What: If your organization uses Cisco Secure Firewall Management Center, an attacker with no credentials whatsoever can reach it over the internet, bypass login, and gain root control of the device — effectively owning your network perimeter. This is a perfect CVSS 10 and is already being actively exploited.
Why it moved: Actively exploited · Widely deployed · Critical severity · 76% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch Cisco FMC to the latest fixed release immediately.
- KEV#2 · CVE-2026-33824
Microsoft
What: A flaw in Microsoft's IKE (VPN/IPsec) service allows remote code execution with no user interaction required, putting any Windows system running IKE-based VPN services at risk of full takeover. This is actively exploited with 73% exploit odds.
Why it moved: Actively exploited · Everyone runs this · Critical severity · 73% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply the Microsoft patch for CVE-2026-33824 across all Windows systems now.
- KEV#3 · CVE-2026-8037
Progress
What: Progress LoadMaster — a widely used load balancer — has a command injection flaw that any unauthenticated attacker can exploit to run arbitrary commands on the appliance; exploit probability is essentially 100% and it is actively being used in the wild. Compromise of a load balancer can expose your entire internal application infrastructure.
Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Update Progress LoadMaster to the patched version without delay.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 11M
- Relationships
- 67M
- Threat actors
- 281
- Indicators
- 644k
- Feeds live
- 19
- Sources total
- 21
Ingest paused — figures are the last-good snapshot, not live.
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.